Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
silverstripe silverstripe 2.3.7 vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2010-5093
Member_ProfileForm in security/Member.php in SilverStripe 2.3.x prior to 2.3.7 allows remote malicious users to hijack user accounts by saving data using the email address (ID) of another user.
Silverstripe Silverstripe 2.3.4
Silverstripe Silverstripe 2.3.0
Silverstripe Silverstripe 2.3.1
Silverstripe Silverstripe 2.3.3
Silverstripe Silverstripe 2.3.5
Silverstripe Silverstripe 2.3.6
Silverstripe Silverstripe 2.3.2
5
CVSSv2
CVE-2010-5094
The deleteinstallfiles function in control/ContentController.php in SilverStripe 2.3.x prior to 2.3.7 does not require ADMIN permissions, which allows remote malicious users to delete index.php and "disrupt mod_rewrite-less URL routing."
Silverstripe Silverstripe 2.3.4
Silverstripe Silverstripe 2.3.0
Silverstripe Silverstripe 2.3.1
Silverstripe Silverstripe 2.3.3
Silverstripe Silverstripe 2.3.5
Silverstripe Silverstripe 2.3.6
Silverstripe Silverstripe 2.3.2
4.3
CVSSv2
CVE-2011-4958
Cross-site scripting (XSS) vulnerability in the process function in SSViewer.php in SilverStripe prior to 2.3.13 and 2.4.x prior to 2.4.6 allows remote malicious users to inject arbitrary web script or HTML via the QUERY_STRING to template placeholders, as demonstrated by a reque...
Silverstripe Silverstripe 2.3.4
Silverstripe Silverstripe 2.3.0
Silverstripe Silverstripe 2.3.7
Silverstripe Silverstripe 2.3.10
Silverstripe Silverstripe 2.3.1
Silverstripe Silverstripe 2.3.3
Silverstripe Silverstripe 2.4.1
Silverstripe Silverstripe 2.3.8
Silverstripe Silverstripe 2.4.0
Silverstripe Silverstripe 2.4.2
Silverstripe Silverstripe
Silverstripe Silverstripe 2.4.4
Silverstripe Silverstripe 2.3.5
Silverstripe Silverstripe 2.3.9
Silverstripe Silverstripe 2.4.3
Silverstripe Silverstripe 2.3.6
Silverstripe Silverstripe 2.3.11
Silverstripe Silverstripe 2.3.2
Silverstripe Silverstripe 2.4.5
1 EDB exploit
4.3
CVSSv2
CVE-2012-4968
Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe 2.3.x prior to 2.3.13 and 2.4.x prior to 2.4.7 allow remote malicious users to inject arbitrary web script or HTML via (1) a crafted string to the AbsoluteLinks, (2) BigSummary, (3) ContextSummary, (4) EscapeXML,...
Silverstripe Silverstripe 2.3.4
Silverstripe Silverstripe 2.3.7
Silverstripe Silverstripe 2.3.10
Silverstripe Silverstripe 2.3.12
Silverstripe Silverstripe 2.3.3
Silverstripe Silverstripe 2.3.8
Silverstripe Silverstripe 2.3.1
Silverstripe Silverstripe 2.3.5
Silverstripe Silverstripe 2.3.9
Silverstripe Silverstripe 2.3.6
Silverstripe Silverstripe 2.3.11
Silverstripe Silverstripe 2.3.0
Silverstripe Silverstripe 2.3.2
Silverstripe Silverstripe 2.4.6
Silverstripe Silverstripe 2.4.1
Silverstripe Silverstripe 2.4.0
Silverstripe Silverstripe 2.4.2
Silverstripe Silverstripe 2.4.3
Silverstripe Silverstripe 2.4.5
4.3
CVSSv2
CVE-2010-4823
Cross-site scripting (XSS) vulnerability in the httpError method in sapphire/core/control/RequestHandler.php in SilverStripe 2.3.x prior to 2.3.10 and 2.4.x prior to 2.4.4, when custom error handling is not used, allows remote malicious users to inject arbitrary web script or HTM...
Silverstripe Silverstripe 2.3.4
Silverstripe Silverstripe 2.3.7
Silverstripe Silverstripe 2.3.3
Silverstripe Silverstripe 2.3.8
Silverstripe Silverstripe 2.3.1
Silverstripe Silverstripe 2.3.5
Silverstripe Silverstripe 2.3.9
Silverstripe Silverstripe 2.3.6
Silverstripe Silverstripe 2.3.0
Silverstripe Silverstripe 2.3.2
Silverstripe Silverstripe 2.4.1
Silverstripe Silverstripe 2.4.0
Silverstripe Silverstripe 2.4.2
Silverstripe Silverstripe 2.4.3
4.3
CVSSv2
CVE-2010-5187
SilverStripe 2.3.x prior to 2.3.8 and 2.4.x prior to 2.4.1, when running on servers with certain configurations, allows remote malicious users to obtain sensitive information via a direct request to PHP files in the (1) sapphire, (2) cms, or (3) mysite folders, which reveals the ...
Silverstripe Silverstripe 2.3.4
Silverstripe Silverstripe 2.3.0
Silverstripe Silverstripe 2.3.7
Silverstripe Silverstripe 2.3.1
Silverstripe Silverstripe 2.3.3
Silverstripe Silverstripe 2.4.0
Silverstripe Silverstripe 2.3.5
Silverstripe Silverstripe 2.3.6
Silverstripe Silverstripe 2.3.2
4.3
CVSSv2
CVE-2010-5089
SilverStripe prior to 2.4.2 does not properly restrict access to pages in draft mode, which allows remote malicious users to obtain sensitive information.
Silverstripe Silverstripe 2.3.4
Silverstripe Silverstripe 2.3.0
Silverstripe Silverstripe 2.3.7
Silverstripe Silverstripe 2.3.10
Silverstripe Silverstripe 2.1.0
Silverstripe Silverstripe 2.2.0
Silverstripe Silverstripe 2.3.1
Silverstripe Silverstripe 2.3.3
Silverstripe Silverstripe 2.2.2
Silverstripe Silverstripe 2.0.0
Silverstripe Silverstripe 2.3.8
Silverstripe Silverstripe 2.4.0
Silverstripe Silverstripe
Silverstripe Silverstripe 2.2.4
Silverstripe Silverstripe 2.3.5
Silverstripe Silverstripe 2.3.9
Silverstripe Silverstripe 2.2.1
Silverstripe Silverstripe 2.1.1
Silverstripe Silverstripe 2.3.6
Silverstripe Silverstripe 2.0.2
Silverstripe Silverstripe 2.0.1
Silverstripe Silverstripe 2.3.2
4
CVSSv2
CVE-2010-5090
SilverStripe prior to 2.4.2 allows remote authenticated users to change administrator passwords via vectors related to admin/security.
Silverstripe Silverstripe 2.3.4
Silverstripe Silverstripe 2.3.0
Silverstripe Silverstripe 2.3.7
Silverstripe Silverstripe 2.3.10
Silverstripe Silverstripe 2.1.0
Silverstripe Silverstripe 2.2.0
Silverstripe Silverstripe 2.3.1
Silverstripe Silverstripe 2.3.3
Silverstripe Silverstripe 2.2.2
Silverstripe Silverstripe 2.0.0
Silverstripe Silverstripe 2.3.8
Silverstripe Silverstripe 2.4.0
Silverstripe Silverstripe
Silverstripe Silverstripe 2.2.4
Silverstripe Silverstripe 2.3.5
Silverstripe Silverstripe 2.3.9
Silverstripe Silverstripe 2.2.1
Silverstripe Silverstripe 2.1.1
Silverstripe Silverstripe 2.3.6
Silverstripe Silverstripe 2.0.2
Silverstripe Silverstripe 2.0.1
Silverstripe Silverstripe 2.3.2
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37316
firmware
CVE-2024-30078
CVE-2024-5995
remote code execution
logic flaw
CVE-2024-20693
CVE-2024-37315
CVE-2024-5464
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2