10
CVE-2013-6955
- EPSS 83.31%
- Veröffentlicht 09.01.2014 18:07:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle cret@cert.org
- Teams Watchlist Login
- Unerledigt Login
webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 allows remote attackers to append data to arbitrary files, and consequently execute arbitrary code, via a pathname in the SLICEUPLOAD X-TMP-FILE HTTP header.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Synology ≫ Diskstation Manager Version4.0
Synology ≫ Diskstation Manager Version4.2
Synology ≫ Diskstation Manager Version4.3
Synology ≫ Diskstation Manager Version4.3-3810
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 83.31% | 0.992 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|