CVE-2017-12080

CVE-2017-12080

Vendor Synology
Product Photo Station
Weakness CWE-200 · Info exposure
Published December 4, 2017
Last update September 16, 2024

CVSS base score

What the vulnerability does

01Description

An information exposure vulnerability in default HTTP configuration file in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain sensitive system information via .htaccess file.

Key dates

02Disclosure timeline

December 4, 2017 CVE published
September 16, 2024 Record updated