CVE-2015-6909
11.09.2015, 16:59
Cross-site scripting (XSS) vulnerability in the "Create download task via file upload" feature in Synology Download Station before 3.5-2962 allows remote attackers to inject arbitrary web script or HTML via the name element in the Info dictionary in a torrent file.
Vendor | Product | Version |
---|---|---|
synology | download_station | 𝑥 ≤ 3.5-2956 |
𝑥
= Vulnerable software versions
References