CVE-2015-6910

Synology Video Station < 1.5-0754 - SQL Injection via id Parameter

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in Synology Video Station before 1.5-0757 allows remote attackers to execute arbitrary SQL commands via the id parameter to audiotrack.cgi.

Scores

EPSS 0.0063
EPSS Percentile 70.4%

Details

CWE
CWE-89
Status published
Products (1)
synology/video_station < 1.5-0754
Published Sep 11, 2015
Tracked Since Feb 18, 2026