Synology DSM 4.3-3776 XSS / File Disclosure / Command Injection

Summary
Synology DiskStation Manager is prone to multiple vulnerabilities.
Impact
Please see the references for details about the impact.
Solution
Vendor updates are available.
Insight
Synology DSM versions 4.3-3776 and below suffer from remote file download, content disclosure, cross site scripting, and command injection vulnerabilities.
Affected
Synology DSM versions 4.3-3776 and below.
Detection
Tries to read /etc/synoinfo.conf by sending a special crafted HTTP GET request.
References