CVE-2013-6955
webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 allows remote attackers to append data to arbitrary files, and consequently execute arbitrary code, via a pathname in the SLICEUPLOAD X-TMP-FILE HTTP header.
- Affected products
- Synology Diskstation Manager
- Synology Diskstation Manager
- = 4.0, 4.2, 4.3, 4.3-3810
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- EPSS
- 84.6% (100th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2014-01-09
CVE-2013-6955 at NVD
5 known exploits for CVE-2013-6955
Proof-of-concept code and exploit modules indexed by Sploitus
Synology DiskStation Manager远程命令执行漏洞
Synology DiskStation Manager SLICEUPLOAD Remote Command Execution
Synology DiskStation Manager - SLICEUPLOAD Remote Command Execution (Metasploit)
Synology DiskStation Manager SLICEUPLOAD Remote Command Execution
Synology DiskStation Manager SLICEUPLOAD Remote Command Execution