Page 8 of 48 results (0.023 seconds)

CVSS: 5.0EPSS: 1%CPEs: 11EXPL: 2

SilverStripe 2.3.x before 2.3.6 allows remote attackers to obtain sensitive information via the (1) debug_memory parameter to core/control/Director.php or (2) debug_profile parameter to main.php. SilverStripe v2.3.x anterior a v2.3.6 permite a atacantes remotos obtener información sensible a través de (1) el parámetro debug_memory a core/control/Director.php o (2) el parámetro debug_profile a main.php. • http://doc.silverstripe.org/sapphire/en/trunk/changelogs//2.3.6 http://groups.google.com/group/silverstripe-announce/browse_thread/thread/c75fbd7926ed2725?tvc=2&fwc=1 http://open.silverstripe.org/changeset/98229 http://open.silverstripe.org/changeset/98230 http://secunia.com/advisories/38697 http://www.openwall.com/lists/oss-security/2012/05/01/3 http://www.osvdb.org/62541 http://www.securityfocus.com/bid/38394 https://exchange.xforce.ibmcloud.com/vulnerabilities/56546 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 4.3EPSS: 0%CPEs: 11EXPL: 0

Cross-site scripting (XSS) vulnerability in SilverStripe 2.3.x before 2.3.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to DataObjectSet pagination. Vulnerabilidad de ejecución de código en sitios cruzados (XSS) en SilverStripe v2.3.x anterior a v2.3.6 permite a atacantes remotos inyectar código web o HTML arbitrario a través de vectores relacionados con la paginación DataObjectSet. • http://doc.silverstripe.org/sapphire/en/trunk/changelogs//2.3.6 http://groups.google.com/group/silverstripe-announce/browse_thread/thread/c75fbd7926ed2725?tvc=2&fwc=1 http://secunia.com/advisories/38697 http://www.openwall.com/lists/oss-security/2012/04/30/1 http://www.openwall.com/lists/oss-security/2012/04/30/3 http://www.openwall.com/lists/oss-security/2012/05/01/3 http://www.osvdb.org/62541 http://www.securityfocus.com/bid/38394 http://www.silverstripe. • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.8EPSS: 0%CPEs: 17EXPL: 0

Multiple cross-site request forgery (CSRF) vulnerabilities in SilverStripe 2.3.x before 2.3.9 and 2.4.x before 2.4.3 allow remote attackers to hijack the authentication of administrators via destructive controller actions, a different vulnerability than CVE-2010-5087. Múltiples vulnerabilidades de solicitudes falsificadas en sitios cruzados (CSRF) en SilverStripe v2.3.x anterior a v2.3.9 y v2.4.x anterior a v2.4.3 permite a atacantes remotos secuestrar la autenticación de los administradores a través de acciones destructivas del controlador, una vulnerabilidad diferente de CVE-2010-5087. • http://doc.silverstripe.org/sapphire/en/trunk/changelogs//2.3.9 http://doc.silverstripe.org/sapphire/en/trunk/changelogs//2.4.3 http://holisticinfosec.org/content/view/157/45 http://open.silverstripe.org/changeset/113275 http://open.silverstripe.org/changeset/113282 http://secunia.com/advisories/41717 http://www.openwall.com/lists/oss-security/2011/01/03/12 http://www.openwall.com/lists/oss-security/2012/04/30/1 http://www.openwall.com/lists/oss-security/2012&# • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 1.9EPSS: 0%CPEs: 1EXPL: 0

The Add Member dialog in the Security admin page in SilverStripe 2.4.0 saves user passwords in plaintext, which allows local users to obtain sensitive information by reading a database. El diálogo Add Member en la página de administración de seguridad en SilverStripe v2.4.0 guarda las contraseñas de usuario en texto plano sin cifrar, lo que permite a usuarios locales obtener información sensible a través de la lectura de la base de datos. • http://doc.silverstripe.org/sapphire/en/trunk/changelogs//2.4.1 http://open.silverstripe.org/changeset/107532 http://open.silverstripe.org/ticket/5772 http://www.openwall.com/lists/oss-security/2012/04/30/1 http://www.openwall.com/lists/oss-security/2012/04/30/3 http://www.openwall.com/lists/oss-security/2012/05/01/3 • CWE-255: Credentials Management Errors •

CVSS: 6.0EPSS: 0%CPEs: 14EXPL: 1

The setName function in filesystem/File.php in SilverStripe 2.3.x before 2.3.8 and 2.4.x before 2.4.1 allows remote authenticated users with CMS author privileges to execute arbitrary PHP code by changing the extension of an uploaded file. La función setName en filesystem/File.php in SilverStripe v2.3.x anterior a v2.3.8 y v2.4.x anterior a v2.4.1 permite a usuarios remotos autenticados con privilegios de autor del CMS ejecutar código PHP arbitrario cambiando la extensión de un fichero subido. • http://dl.packetstormsecurity.net/1006-exploits/silverstripe-shell.txt http://doc.silverstripe.org/sapphire/en/trunk/changelogs//2.3.8 http://doc.silverstripe.org/sapphire/en/trunk/changelogs//2.4.1 http://open.silverstripe.org/changeset/107273 http://open.silverstripe.org/ticket/5693 http://www.openwall.com/lists/oss-security/2012/04/30/1 http://www.openwall.com/lists/oss-security/2012/04/30/3 http://www.openwall.com/lists/oss-security/2012/05/01/3 • CWE-94: Improper Control of Generation of Code ('Code Injection') •