6
CVE-2010-5091
- EPSS 0.87%
- Veröffentlicht 26.08.2012 18:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
The setName function in filesystem/File.php in SilverStripe 2.3.x before 2.3.8 and 2.4.x before 2.4.1 allows remote authenticated users with CMS author privileges to execute arbitrary PHP code by changing the extension of an uploaded file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Silverstripe ≫ Silverstripe Version2.3.0
Silverstripe ≫ Silverstripe Version2.3.0 Updaterc1
Silverstripe ≫ Silverstripe Version2.3.0 Updaterc2
Silverstripe ≫ Silverstripe Version2.3.0 Updaterc3
Silverstripe ≫ Silverstripe Version2.3.1
Silverstripe ≫ Silverstripe Version2.3.1 Updaterc1
Silverstripe ≫ Silverstripe Version2.3.1 Updaterc2
Silverstripe ≫ Silverstripe Version2.3.2
Silverstripe ≫ Silverstripe Version2.3.3
Silverstripe ≫ Silverstripe Version2.3.4
Silverstripe ≫ Silverstripe Version2.3.5
Silverstripe ≫ Silverstripe Version2.3.6
Silverstripe ≫ Silverstripe Version2.3.7
Silverstripe ≫ Silverstripe Version2.4.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.87% | 0.747 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6 | 6.8 | 6.4 |
AV:N/AC:M/Au:S/C:P/I:P/A:P
|
CWE-94 Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.