Unrated severityNVD Advisory· Published Sep 29, 2010· Updated Apr 29, 2026
CVE-2010-2453
CVE-2010-2453
Description
Multiple cross-site scripting (XSS) vulnerabilities in Synology Disk Station 2.x before DSM3.0-1337 allow remote attackers to inject arbitrary web script or HTML by connecting to the FTP server and providing a crafted (1) USER or (2) PASS command, which is written by the FTP logging module to a web-interface log window, related to a "web commands injection" issue.
Affected products
10cpe:2.3:o:synology:dsm:2.2-0942:*:*:*:*:*:*:*+ 9 more
- cpe:2.3:o:synology:dsm:2.2-0942:*:*:*:*:*:*:*
- cpe:2.3:o:synology:dsm:2.2-1041:*:*:*:*:*:*:*
- cpe:2.3:o:synology:dsm:2.2-1042:*:*:*:*:*:*:*
- cpe:2.3:o:synology:dsm:2.2-1045:*:*:*:*:*:*:*
- cpe:2.3:o:synology:dsm:2.3-1139:*:*:*:*:*:*:*
- cpe:2.3:o:synology:dsm:2.3-1141:*:*:*:*:*:*:*
- cpe:2.3:o:synology:dsm:2.3-1144:*:*:*:*:*:*:*
- cpe:2.3:o:synology:dsm:2.3-1157:*:*:*:*:*:*:*
- cpe:2.3:o:synology:dsm:2.3-1161:*:*:*:*:*:*:*
- cpe:2.3:o:synology:dsm:3.0-1334:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.