CVE-2017-12079
04.12.2017, 19:29
Files or directories accessible to external parties vulnerability in picasa.php in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain arbitrary files via prog_id field.Enginsight
Vendor | Product | Version |
---|---|---|
synology | photo_station | 6.8 ≤ 𝑥 < 6.8.1-3458 |
synology | photo_station | 6.3 ≤ 𝑥 < 6.3-2970 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-552 - Files or Directories Accessible to External PartiesThe product makes files or directories accessible to unauthorized actors, even though they should not be.
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.