Vulnerability Details CVE-2016-10322
Synology Photo Station before 6.3-2958 allows remote authenticated guest users to execute arbitrary commands via shell metacharacters in the X-Forwarded-For HTTP header to photo/login.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.028
EPSS Ranking 85.5%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
Products affected by CVE-2016-10322
-
cpe:2.3:a:synology:photo_station:5.2-2398
-
cpe:2.3:a:synology:photo_station:5.2-2413
-
cpe:2.3:a:synology:photo_station:6.0-2636
-
cpe:2.3:a:synology:photo_station:6.0-2638
-
cpe:2.3:a:synology:photo_station:6.0-2639
-
cpe:2.3:a:synology:photo_station:6.0-2640
-
cpe:2.3:a:synology:photo_station:6.3
-
cpe:2.3:a:synology:photo_station:6.3-2944