Vulnerability Database

291,049

Total vulnerabilities in the database

CVE-2015-4656

Multiple cross-site scripting (XSS) vulnerabilities in Synology Photo Station before 6.3-2945 allow remote attackers to inject arbitrary web script or HTML via the (1) success parameter to login.php or (2) crafted URL parameters to index.php, as demonstrated by the t parameter to photo/.

  • Published: Jun 18, 2015
  • Updated: Apr 13, 2023
  • CVE: CVE-2015-4656
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:N/I:P/A:N