Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-10443 PoC — Synology BeePhotos 命令注入漏洞

Source
Associated Vulnerability
Title:Synology BeePhotos 命令注入漏洞 (CVE-2024-10443)
Description:Synology BeePhotos是中国群晖科技(Synology)公司的一个照片备份程序。 Synology BeePhotos 1.0.2-10026和1.1.0-10053之前版本存在命令注入漏洞,该漏洞源于任务管理器组件中特殊元素中和不当,从而允许远程攻击者通过未指定的向量执行任意代码。
Description
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attackers to execute arbitrary code via unspecified vectors.
File Snapshot

id: CVE-2024-10443 info: name: Synology BeeStation BST150-4T - Unauthenticated Command Injection ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.