4.3

CVE-2010-1593

Exploit
Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via (1) the CommenterURL parameter to PostCommentForm, and in the Forum module before 0.2.5 in SilverStripe before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via (2) the Search parameter to forums/search (aka the search script).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SilverstripeSilverstripe Version <= 2.3.4
SilverstripeSilverstripe Version2.0.0
SilverstripeSilverstripe Version2.0.1
SilverstripeSilverstripe Version2.0.2
SilverstripeSilverstripe Version2.1.0
SilverstripeSilverstripe Version2.1.1
SilverstripeSilverstripe Version2.2.0
SilverstripeSilverstripe Version2.2.1
SilverstripeSilverstripe Version2.2.2
SilverstripeSilverstripe Version2.2.4
SilverstripeSilverstripe Version2.3.0
SilverstripeSilverstripe Version2.3.0 Updaterc1
SilverstripeSilverstripe Version2.3.0 Updaterc2
SilverstripeSilverstripe Version2.3.0 Updaterc3
SilverstripeSilverstripe Version2.3.1
SilverstripeSilverstripe Version2.3.1 Updaterc1
SilverstripeSilverstripe Version2.3.1 Updaterc2
SilverstripeSilverstripe Version2.3.2
SilverstripeSilverstripe Version2.3.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.6% 0.833
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0450.html
Exploit
http://groups.google.com/group/silverstripe-announce/browse_thread/thread/f51749342eee9456
Patch
http://open.silverstripe.org/changeset/97074
Patch
Exploit
http://open.silverstripe.org/wiki/ChangeLog/2.3.5
http://osvdb.org/61921
http://osvdb.org/61923
http://secunia.com/advisories/38290
Vendor Advisory
http://secunia.com/advisories/38347
Vendor Advisory
http://www.securityfocus.com/archive/1/509139/100/0/threaded
http://www.securityfocus.com/bid/37923
Patch
http://www.silverstripe.org/security-releases/
Patch
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/55838
https://exchange.xforce.ibmcloud.com/vulnerabilities/55839