Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Audio Station before 6.5.4-3367 allows remote authenticated users to delete arbitrary files via unspecified vectors.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Synology Audio Station 路径遍历漏洞
Vulnerability Description
Synology Audio Station是中国Synology公司的一种供用户存储和共享其音乐收藏以及连接网络电台的方式。允许在各种设备上进行高质量播放。 Synology Audio Station 6.5.4-3367之前版本存在路径遍历漏洞,该漏洞源于webapi 对受限目录的路径名的不当限制(路径遍历),远程攻击者利用该漏洞可以通过未指定的向量删除任意文件。
CVSS Information
N/A
Vulnerability Type
N/A