CVE-2015-6910
Synology Video Station < 1.5-0754 - SQL Injection via id Parameter
Title source: llmDescription
SQL injection vulnerability in Synology Video Station before 1.5-0757 allows remote attackers to execute arbitrary SQL commands via the id parameter to audiotrack.cgi.
References (6)
Core 6
Core References
Vendor Advisory x_refsource_confirm
https://www.synology.com/en-global/support/security/Video_Station_1_5_0757
Exploit x_refsource_misc
https://www.securify.nl/advisory/SFY20150810/synology_video_station_command_injection_and_multiple_sql_injection_vulnerabilities.html
Vendor Advisory x_refsource_confirm
https://www.synology.com/en-global/releaseNote/VideoStation?model=DS715
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/536427/100/0/threaded
Mailing List mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Sep/31
Scores
EPSS
0.0063
EPSS Percentile
70.4%
Details
CWE
CWE-89
Status
published
Products (1)
synology/video_station
< 1.5-0754
Published
Sep 11, 2015
Tracked Since
Feb 18, 2026