CVE-2015-9105

Multiple cross-site scripting (XSS) vulnerabilities in Synology Video Station 1.2 before 1.2-0455, 1.5 before 1.5-0772, and 1.6 before 1.6-0847 allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) file name or (2) collection name of videos.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:synology:video_station:1.2-0439:*:*:*:*:*:*:*
cpe:2.3:a:synology:video_station:1.2-0443:*:*:*:*:*:*:*
cpe:2.3:a:synology:video_station:1.2-0447:*:*:*:*:*:*:*
cpe:2.3:a:synology:video_station:1.2-0451:*:*:*:*:*:*:*
cpe:2.3:a:synology:video_station:1.2-0453:*:*:*:*:*:*:*
cpe:2.3:a:synology:video_station:1.5-0753:*:*:*:*:*:*:*
cpe:2.3:a:synology:video_station:1.5-0754:*:*:*:*:*:*:*
cpe:2.3:a:synology:video_station:1.5-0757:*:*:*:*:*:*:*
cpe:2.3:a:synology:video_station:1.5-0763:*:*:*:*:*:*:*
cpe:2.3:a:synology:video_station:1.5-0770:*:*:*:*:*:*:*
cpe:2.3:a:synology:video_station:1.6-0835:*:*:*:*:*:*:*
cpe:2.3:a:synology:video_station:1.6-0840:*:*:*:*:*:*:*
cpe:2.3:a:synology:video_station:1.6-0841:*:*:*:*:*:*:*
cpe:2.3:a:synology:video_station:1.6-0844:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-06-30 13:29

Updated : 2024-02-04 19:29


NVD link : CVE-2015-9105

Mitre link : CVE-2015-9105

CVE.ORG link : CVE-2015-9105


JSON object : View

Products Affected

synology

  • video_station
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')