Show filters
96 Total Results
Displaying 91-96 of 96
Sort by:
Attacker Value
Unknown
CVE-2010-5080
Disclosure Date: August 26, 2012 (last updated October 04, 2023)
The Security/changepassword URL action in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 passes a token as a GET parameter while changing a password through email, which allows remote attackers to obtain sensitive data and hijack the session via the HTTP referer logs on a server, aka "HTTP referer leakage."
0
Attacker Value
Unknown
CVE-2012-0976
Disclosure Date: February 02, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in admin/EditForm in SilverStripe 2.4.6 allows remote authenticated users with Content Authors privileges to inject arbitrary web script or HTML via the Title parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2010-1593
Disclosure Date: April 28, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via (1) the CommenterURL parameter to PostCommentForm, and in the Forum module before 0.2.5 in SilverStripe before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via (2) the Search parameter to forums/search (aka the search script).
0
Attacker Value
Unknown
CVE-2008-6753
Disclosure Date: April 27, 2009 (last updated October 04, 2023)
SQL injection vulnerability in SilverStripe before 2.2.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to AjaxUniqueTextField.
0
Attacker Value
Unknown
CVE-2009-1433
Disclosure Date: April 24, 2009 (last updated October 04, 2023)
SQL injection vulnerability in File::find (filesystem/File.php) in SilverStripe before 2.3.1 allows remote attackers to execute arbitrary SQL commands via the filename parameter.
0
Attacker Value
Unknown
CVE-2007-2321
Disclosure Date: April 27, 2007 (last updated October 04, 2023)
Unspecified vulnerability in the search functionality in SilverStripe 2.0.0 has unknown impact and attack vectors.
0