VYPR
Unrated severityNVD Advisory· Published Sep 29, 2010· Updated Apr 29, 2026

CVE-2010-2453

CVE-2010-2453

Description

Multiple cross-site scripting (XSS) vulnerabilities in Synology Disk Station 2.x before DSM3.0-1337 allow remote attackers to inject arbitrary web script or HTML by connecting to the FTP server and providing a crafted (1) USER or (2) PASS command, which is written by the FTP logging module to a web-interface log window, related to a "web commands injection" issue.

Affected products

10
  • Synology/Dsm10 versions
    cpe:2.3:o:synology:dsm:2.2-0942:*:*:*:*:*:*:*+ 9 more
    • cpe:2.3:o:synology:dsm:2.2-0942:*:*:*:*:*:*:*
    • cpe:2.3:o:synology:dsm:2.2-1041:*:*:*:*:*:*:*
    • cpe:2.3:o:synology:dsm:2.2-1042:*:*:*:*:*:*:*
    • cpe:2.3:o:synology:dsm:2.2-1045:*:*:*:*:*:*:*
    • cpe:2.3:o:synology:dsm:2.3-1139:*:*:*:*:*:*:*
    • cpe:2.3:o:synology:dsm:2.3-1141:*:*:*:*:*:*:*
    • cpe:2.3:o:synology:dsm:2.3-1144:*:*:*:*:*:*:*
    • cpe:2.3:o:synology:dsm:2.3-1157:*:*:*:*:*:*:*
    • cpe:2.3:o:synology:dsm:2.3-1161:*:*:*:*:*:*:*
    • cpe:2.3:o:synology:dsm:3.0-1334:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.