CVE-2010-2453

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
29/09/2010
Last modified:
11/04/2025

Description

Multiple cross-site scripting (XSS) vulnerabilities in Synology Disk Station 2.x before DSM3.0-1337 allow remote attackers to inject arbitrary web script or HTML by connecting to the FTP server and providing a crafted (1) USER or (2) PASS command, which is written by the FTP logging module to a web-interface log window, related to a "web commands injection" issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:synology:dsm:2.2-0942:*:*:*:*:*:*:*
cpe:2.3:o:synology:dsm:2.2-1041:*:*:*:*:*:*:*
cpe:2.3:o:synology:dsm:2.2-1042:*:*:*:*:*:*:*
cpe:2.3:o:synology:dsm:2.2-1045:*:*:*:*:*:*:*
cpe:2.3:o:synology:dsm:2.3-1139:*:*:*:*:*:*:*
cpe:2.3:o:synology:dsm:2.3-1141:*:*:*:*:*:*:*
cpe:2.3:o:synology:dsm:2.3-1144:*:*:*:*:*:*:*
cpe:2.3:o:synology:dsm:2.3-1157:*:*:*:*:*:*:*
cpe:2.3:o:synology:dsm:2.3-1161:*:*:*:*:*:*:*
cpe:2.3:o:synology:dsm:3.0-1334:*:*:*:*:*:*:*
cpe:2.3:h:synology:disk_station_ds1010\+:*:*:*:*:*:*:*:*
cpe:2.3:h:synology:disk_station_ds109:*:*:*:*:*:*:*:*
cpe:2.3:h:synology:disk_station_ds110\+:*:*:*:*:*:*:*:*
cpe:2.3:h:synology:disk_station_ds110j:*:*:*:*:*:*:*:*
cpe:2.3:h:synology:disk_station_ds209:*:*:*:*:*:*:*:*