CVE-2018-13284

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
01/04/2019
Last modified:
14/01/2025

Description

Command injection vulnerability in ftpd in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to execute arbitrary OS commands via the (1) MKD or (2) RMD command.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:* 5.2 (including) 5.2-5967-8 (excluding)
cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:* 6.0 (including) 6.0.3-8754-8 (excluding)
cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:* 6.1 (including) 6.1.7-15284-1 (excluding)
cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:* 6.2 (including) 6.2-23739-1 (excluding)