Silverstripe

Silverstripe

64 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.73%
  • Veröffentlicht 17.09.2012 17:55:02
  • Zuletzt bearbeitet 16.06.2026 23:25:36

Cross-site scripting (XSS) vulnerability in the httpError method in sapphire/core/control/RequestHandler.php in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4, when custom error handling is not used, allows remote attackers to inject arbitra...

Exploit
  • EPSS 2.56%
  • Veröffentlicht 17.09.2012 17:55:02
  • Zuletzt bearbeitet 16.06.2026 23:25:36

SQL injection vulnerability in the augmentSQL method in core/model/Translatable.php in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4, when the Translatable extension is enabled, allows remote attackers to execute arbitrary SQL commands via ...

  • EPSS 1.9%
  • Veröffentlicht 17.09.2012 17:55:02
  • Zuletzt bearbeitet 16.06.2026 23:26:05

SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain version information via a direct request to (1) apphire/silverstripe_ver...

Exploit
  • EPSS 1.45%
  • Veröffentlicht 17.09.2012 17:55:02
  • Zuletzt bearbeitet 16.06.2026 23:35:43

SQL injection vulnerability in the addslashes method in SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6, when connected to a MySQL database using far east character encodings, allows remote attackers to execute arbitrary SQL commands via unsp...

Exploit
  • EPSS 1.35%
  • Veröffentlicht 17.09.2012 17:55:02
  • Zuletzt bearbeitet 16.06.2026 23:35:43

SQL injection vulnerability in the Folder::findOrMake method in SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • EPSS 1.6%
  • Veröffentlicht 17.09.2012 17:55:02
  • Zuletzt bearbeitet 16.06.2026 23:35:43

SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote authenticated users with the EDIT_PERMISSIONS permission to gain administrator privileges via a TreeMultiselectField that includes admin groups when adding a user to the selected g...

Exploit
  • EPSS 3.92%
  • Veröffentlicht 17.09.2012 17:55:02
  • Zuletzt bearbeitet 16.06.2026 23:35:43

code/sitefeatures/PageCommentInterface.php in SilverStripe 2.4.x before 2.4.6 might allow remote attackers to execute arbitrary code via a crafted cookie in a user comment submission, which is not properly handled when it is deserialized.

Exploit
  • EPSS 2.04%
  • Veröffentlicht 26.08.2012 18:55:01
  • Zuletzt bearbeitet 16.06.2026 23:26:17

SilverStripe 2.3.x before 2.3.6 allows remote attackers to obtain sensitive information via the (1) debug_memory parameter to core/control/Director.php or (2) debug_profile parameter to main.php.

  • EPSS 1.22%
  • Veröffentlicht 26.08.2012 18:55:01
  • Zuletzt bearbeitet 16.06.2026 23:26:06

The Security/changepassword URL action in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 passes a token as a GET parameter while changing a password through email, which allows remote attackers to obtain sensitive data and hijack the session...

Exploit
  • EPSS 2.96%
  • Veröffentlicht 26.08.2012 18:55:01
  • Zuletzt bearbeitet 16.06.2026 23:26:06

SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism and hijack the authentication of administrators via vectors related to "form action requests" using a...