CVE-2018-8914
10.05.2018, 13:29
SQL injection vulnerability in UPnP DMA in Synology Media Server before 1.7.6-2842 and before 1.4-2654 allows remote attackers to execute arbitrary SQL commands via the ObjectID parameter.
Vendor | Product | Version |
---|---|---|
synology | media_server | 1.4 ≤ 𝑥 < 1.4-2654 |
synology | media_server | 1.7 ≤ 𝑥 < 1.7.6-2842 |
𝑥
= Vulnerable software versions