Unrestricted file upload vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to create arbitrary PHP scripts via the type parameter.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://www.synology.com/en-global/support/security/Synology_SA_17_34_PhotoStation | vendor advisory |
https://www.exploit-db.com/exploits/42434/ | exploit vdb entry third party advisory |