CVE-2015-9105

Multiple cross-site scripting (XSS) vulnerabilities in Synology Video Station 1.2 before 1.2-0455, 1.5 before 1.5-0772, and 1.6 before 1.6-0847 allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) file name or (2) collection name of videos.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:synology:video_station:1.2-0439:*:*:*:*:*:*:*
cpe:2.3:a:synology:video_station:1.2-0443:*:*:*:*:*:*:*
cpe:2.3:a:synology:video_station:1.2-0447:*:*:*:*:*:*:*
cpe:2.3:a:synology:video_station:1.2-0451:*:*:*:*:*:*:*
cpe:2.3:a:synology:video_station:1.2-0453:*:*:*:*:*:*:*
cpe:2.3:a:synology:video_station:1.5-0753:*:*:*:*:*:*:*
cpe:2.3:a:synology:video_station:1.5-0754:*:*:*:*:*:*:*
cpe:2.3:a:synology:video_station:1.5-0757:*:*:*:*:*:*:*
cpe:2.3:a:synology:video_station:1.5-0763:*:*:*:*:*:*:*
cpe:2.3:a:synology:video_station:1.5-0770:*:*:*:*:*:*:*
cpe:2.3:a:synology:video_station:1.6-0835:*:*:*:*:*:*:*
cpe:2.3:a:synology:video_station:1.6-0840:*:*:*:*:*:*:*
cpe:2.3:a:synology:video_station:1.6-0841:*:*:*:*:*:*:*
cpe:2.3:a:synology:video_station:1.6-0844:*:*:*:*:*:*:*

History

21 Nov 2024, 02:39

Type Values Removed Values Added
References () http://www.fortiguard.com/zeroday/FG-VD-15-107 - Third Party Advisory () http://www.fortiguard.com/zeroday/FG-VD-15-107 - Third Party Advisory
References () http://www.fortiguard.com/zeroday/FG-VD-15-108 - Third Party Advisory () http://www.fortiguard.com/zeroday/FG-VD-15-108 - Third Party Advisory
References () https://www.synology.com/en-global/support/security/Video_station_1_5_0772 - Vendor Advisory () https://www.synology.com/en-global/support/security/Video_station_1_5_0772 - Vendor Advisory

Information

Published : 2017-06-30 13:29

Updated : 2024-11-21 02:39


NVD link : CVE-2015-9105

Mitre link : CVE-2015-9105

CVE.ORG link : CVE-2015-9105


JSON object : View

Products Affected

synology

  • video_station
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')