Command Injection Flaw in Synology Photo Station
CVE-2016-10329
What is CVE-2016-10329?
A command injection vulnerability exists in the login.php file of Synology Photo Station prior to version 6.5.3-3226. This flaw enables remote attackers to manipulate the 'X-Forwarded-For' HTTP header to execute arbitrary commands on the server. This vulnerability poses significant security risks, as it can potentially allow unauthorized access and control over the application. Users are advised to update to the latest version to mitigate any potential threats.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Synology Photo Station All versions prior to version 6.5.3-3226
References
EPSS Score
14% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved