CVE-2010-4823
- EPSS 0.73%
- Veröffentlicht 17.09.2012 17:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the httpError method in sapphire/core/control/RequestHandler.php in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4, when custom error handling is not used, allows remote attackers to inject arbitra...
CVE-2010-4824
- EPSS 1.22%
- Veröffentlicht 17.09.2012 17:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
SQL injection vulnerability in the augmentSQL method in core/model/Translatable.php in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4, when the Translatable extension is enabled, allows remote attackers to execute arbitrary SQL commands via ...
- EPSS 0.72%
- Veröffentlicht 17.09.2012 17:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain version information via a direct request to (1) apphire/silverstripe_ver...
CVE-2011-4959
- EPSS 0.72%
- Veröffentlicht 17.09.2012 17:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
SQL injection vulnerability in the addslashes method in SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6, when connected to a MySQL database using far east character encodings, allows remote attackers to execute arbitrary SQL commands via unsp...
CVE-2011-4960
- EPSS 0.47%
- Veröffentlicht 17.09.2012 17:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
SQL injection vulnerability in the Folder::findOrMake method in SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
- EPSS 0.5%
- Veröffentlicht 17.09.2012 17:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote authenticated users with the EDIT_PERMISSIONS permission to gain administrator privileges via a TreeMultiselectField that includes admin groups when adding a user to the selected g...
CVE-2011-4962
- EPSS 2.69%
- Veröffentlicht 17.09.2012 17:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
code/sitefeatures/PageCommentInterface.php in SilverStripe 2.4.x before 2.4.6 might allow remote attackers to execute arbitrary code via a crafted cookie in a user comment submission, which is not properly handled when it is deserialized.
- EPSS 0.73%
- Veröffentlicht 26.08.2012 18:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
SilverStripe 2.3.x before 2.3.6 allows remote attackers to obtain sensitive information via the (1) debug_memory parameter to core/control/Director.php or (2) debug_profile parameter to main.php.
CVE-2010-5080
- EPSS 0.66%
- Veröffentlicht 26.08.2012 18:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Security/changepassword URL action in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 passes a token as a GET parameter while changing a password through email, which allows remote attackers to obtain sensitive data and hijack the session...
- EPSS 0.78%
- Veröffentlicht 26.08.2012 18:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism and hijack the authentication of administrators via vectors related to "form action requests" using a...