CVE-2016-10329

Publication date

2017-05-12 20:00:00

Family

synology

State

PUBLISHED

Description

Command injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to execute arbitrary code via shell metacharacters in the crafted X-Forwarded-For header.