5
CVSSv2

CVE-2010-5094

Published: 26/08/2012 Updated: 27/08/2012
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The deleteinstallfiles function in control/ContentController.php in SilverStripe 2.3.x prior to 2.3.7 does not require ADMIN permissions, which allows remote malicious users to delete index.php and "disrupt mod_rewrite-less URL routing."

Vulnerable Product Search on Vulmon Subscribe to Product

silverstripe silverstripe 2.3.0

silverstripe silverstripe 2.3.1

silverstripe silverstripe 2.3.3

silverstripe silverstripe 2.3.4

silverstripe silverstripe 2.3.5

silverstripe silverstripe 2.3.6

silverstripe silverstripe 2.3.2