4.3
CVSSv2

CVE-2010-5187

Published: 26/08/2012 Updated: 27/08/2012
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

SilverStripe 2.3.x prior to 2.3.8 and 2.4.x prior to 2.4.1, when running on servers with certain configurations, allows remote malicious users to obtain sensitive information via a direct request to PHP files in the (1) sapphire, (2) cms, or (3) mysite folders, which reveals the installation path in an error message.

Vulnerable Product Search on Vulmon Subscribe to Product

silverstripe silverstripe 2.3.0

silverstripe silverstripe 2.3.1

silverstripe silverstripe 2.3.5

silverstripe silverstripe 2.4.0

silverstripe silverstripe 2.3.3

silverstripe silverstripe 2.3.6

silverstripe silverstripe 2.3.2

silverstripe silverstripe 2.3.7

silverstripe silverstripe 2.3.4