← back
CVE-2016-10329CWE-77

CVE-2016-10329

15Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 41%
exploitation probability
41%top 1% of all CVEs
observed exploitation
nono source reports it
Command injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to execute arbitrary code via shell metacharacters in the crafted 'X-Forwarded-For' header.