CVE-2017-11152
HIGHSynology Photo Station < 6.7.3-3432 Path Traversal & Arbitrary File Write via PixlrEditorHandler.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-11152. PoCs published by Kacper Szurek.
AI-analyzed exploit summary This exploit chains multiple vulnerabilities in Synology Photo Station to achieve remote code execution. It involves session manipulation, arbitrary file upload, and path traversal to execute PHP code as the PhotoStation user.
Description
Directory traversal vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to write arbitrary files via the path parameter.
Exploits (1)
This exploit chains multiple vulnerabilities in Synology Photo Station to achieve remote code execution. It involves session manipulation, arbitrary file upload, and path traversal to execute PHP code as the PhotoStation user.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N