Silverstripe

Silverstripe

64 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.73%
  • Veröffentlicht 17.09.2012 17:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in the httpError method in sapphire/core/control/RequestHandler.php in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4, when custom error handling is not used, allows remote attackers to inject arbitra...

Exploit
  • EPSS 1.22%
  • Veröffentlicht 17.09.2012 17:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

SQL injection vulnerability in the augmentSQL method in core/model/Translatable.php in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4, when the Translatable extension is enabled, allows remote attackers to execute arbitrary SQL commands via ...

  • EPSS 0.72%
  • Veröffentlicht 17.09.2012 17:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain version information via a direct request to (1) apphire/silverstripe_ver...

Exploit
  • EPSS 0.72%
  • Veröffentlicht 17.09.2012 17:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

SQL injection vulnerability in the addslashes method in SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6, when connected to a MySQL database using far east character encodings, allows remote attackers to execute arbitrary SQL commands via unsp...

Exploit
  • EPSS 0.47%
  • Veröffentlicht 17.09.2012 17:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

SQL injection vulnerability in the Folder::findOrMake method in SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • EPSS 0.5%
  • Veröffentlicht 17.09.2012 17:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote authenticated users with the EDIT_PERMISSIONS permission to gain administrator privileges via a TreeMultiselectField that includes admin groups when adding a user to the selected g...

Exploit
  • EPSS 2.69%
  • Veröffentlicht 17.09.2012 17:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

code/sitefeatures/PageCommentInterface.php in SilverStripe 2.4.x before 2.4.6 might allow remote attackers to execute arbitrary code via a crafted cookie in a user comment submission, which is not properly handled when it is deserialized.

Exploit
  • EPSS 0.73%
  • Veröffentlicht 26.08.2012 18:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

SilverStripe 2.3.x before 2.3.6 allows remote attackers to obtain sensitive information via the (1) debug_memory parameter to core/control/Director.php or (2) debug_profile parameter to main.php.

  • EPSS 0.66%
  • Veröffentlicht 26.08.2012 18:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Security/changepassword URL action in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 passes a token as a GET parameter while changing a password through email, which allows remote attackers to obtain sensitive data and hijack the session...

Exploit
  • EPSS 0.78%
  • Veröffentlicht 26.08.2012 18:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism and hijack the authentication of administrators via vectors related to "form action requests" using a...