Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
silverstripe vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2010-5091
The setName function in filesystem/File.php in SilverStripe 2.3.x prior to 2.3.8 and 2.4.x prior to 2.4.1 allows remote authenticated users with CMS author privileges to execute arbitrary PHP code by changing the extension of an uploaded file.
Silverstripe Silverstripe 2.3.7
Silverstripe Silverstripe 2.4.0
Silverstripe Silverstripe 2.3.0
Silverstripe Silverstripe 2.3.3
Silverstripe Silverstripe 2.3.5
Silverstripe Silverstripe 2.3.1
Silverstripe Silverstripe 2.3.2
Silverstripe Silverstripe 2.3.4
Silverstripe Silverstripe 2.3.6
NA
CVE-2010-5094
The deleteinstallfiles function in control/ContentController.php in SilverStripe 2.3.x prior to 2.3.7 does not require ADMIN permissions, which allows remote malicious users to delete index.php and "disrupt mod_rewrite-less URL routing."
Silverstripe Silverstripe 2.3.0
Silverstripe Silverstripe 2.3.1
Silverstripe Silverstripe 2.3.3
Silverstripe Silverstripe 2.3.4
Silverstripe Silverstripe 2.3.5
Silverstripe Silverstripe 2.3.6
Silverstripe Silverstripe 2.3.2
NA
CVE-2010-5187
SilverStripe 2.3.x prior to 2.3.8 and 2.4.x prior to 2.4.1, when running on servers with certain configurations, allows remote malicious users to obtain sensitive information via a direct request to PHP files in the (1) sapphire, (2) cms, or (3) mysite folders, which reveals the ...
Silverstripe Silverstripe 2.3.0
Silverstripe Silverstripe 2.3.1
Silverstripe Silverstripe 2.3.5
Silverstripe Silverstripe 2.4.0
Silverstripe Silverstripe 2.3.3
Silverstripe Silverstripe 2.3.6
Silverstripe Silverstripe 2.3.2
Silverstripe Silverstripe 2.3.7
Silverstripe Silverstripe 2.3.4
NA
CVE-2010-5188
SilverStripe 2.3.x prior to 2.3.6 allows remote malicious users to obtain sensitive information via the (1) debug_memory parameter to core/control/Director.php or (2) debug_profile parameter to main.php.
Silverstripe Silverstripe 2.3.0
Silverstripe Silverstripe 2.3.2
Silverstripe Silverstripe 2.3.3
Silverstripe Silverstripe 2.3.1
Silverstripe Silverstripe 2.3.4
Silverstripe Silverstripe 2.3.5
NA
CVE-2012-0976
Cross-site scripting (XSS) vulnerability in admin/EditForm in SilverStripe 2.4.6 allows remote authenticated users with Content Authors privileges to inject arbitrary web script or HTML via the Title parameter. NOTE: some of these details are obtained from third party information...
Silverstripe Silverstripe 2.4.6
NA
CVE-2010-1593
Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe prior to 2.3.5 allow remote malicious users to inject arbitrary web script or HTML via (1) the CommenterURL parameter to PostCommentForm, and in the Forum module prior to 0.2.5 in SilverStripe prior to 2.3.5 allo...
Silverstripe Silverstripe 2.3.1
Silverstripe Silverstripe 2.1.0
Silverstripe Silverstripe 2.3.3
Silverstripe Silverstripe 2.3.2
Silverstripe Silverstripe 2.1.1
Silverstripe Silverstripe 2.2.2
Silverstripe Silverstripe 2.3.0
Silverstripe Silverstripe 2.0.0
Silverstripe Silverstripe 2.2.1
Silverstripe Silverstripe 2.2.4
Silverstripe Silverstripe 2.0.1
Silverstripe Silverstripe
Silverstripe Silverstripe 2.0.2
Silverstripe Silverstripe 2.2.0
NA
CVE-2008-6753
SQL injection vulnerability in SilverStripe prior to 2.2.2 allows remote malicious users to execute arbitrary SQL commands via unspecified vectors related to AjaxUniqueTextField.
Silverstripe Silverstripe 2.2.0
Silverstripe Silverstripe 2.1.1
Silverstripe Silverstripe 2.1.0
Silverstripe Silverstripe 2.0.2
Silverstripe Silverstripe 2.0.1
Silverstripe Silverstripe 2.0.0
Silverstripe Silverstripe
NA
CVE-2009-1433
SQL injection vulnerability in File::find (filesystem/File.php) in SilverStripe prior to 2.3.1 allows remote malicious users to execute arbitrary SQL commands via the filename parameter.
Silverstripe Silverstripe 2.3.0
Silverstripe Silverstripe 2.1.0
Silverstripe Silverstripe 2.0.1
Silverstripe Silverstripe 2.0.0
Silverstripe Silverstripe 2.2.2
Silverstripe Silverstripe 2.2.1
Silverstripe Silverstripe 2.2.0
Silverstripe Silverstripe 2.1.1
Silverstripe Silverstripe 2.3.1
Silverstripe Silverstripe
Silverstripe Silverstripe 2.2.4
Silverstripe Silverstripe 2.0.2
NA
CVE-2007-2321
Unspecified vulnerability in the search functionality in SilverStripe 2.0.0 has unknown impact and attack vectors.
Silverstripe Silverstripe 2.0.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
validation
CVE-2012-1823
malicious code
CVE-2024-5770
CVE-2023-45866
CVE-2024-35687
local users
CVE-2024-31246
CVE-2024-35730
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
4
5
6
7
8
9