Security Advisory

CVE-2018-13284

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-04-01 14:26:30
Last updated 2024-09-16 17:27:55
Assigner synology
CVSS score 7.5
State PUBLISHED

Description

Command injection vulnerability in ftpd in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to execute arbitrary OS commands via the (1) MKD or (2) RMD command.