5.8
CVSSv2

CVE-2013-2653

Published: 13/11/2013 Updated: 13/11/2013
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 585
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

security/MemberLoginForm.php in SilverStripe 3.0.3 supports login using a GET request, which makes it easier for remote malicious users to conduct phishing attacks without detection by the victim.

Vulnerable Product Search on Vulmon Subscribe to Product

silverstripe silverstripe 3.0.3

Exploits

source: wwwsecurityfocuscom/bid/61578/info SilverStripe is prone to an information-disclosure vulnerability An attacker can exploit this issue to gain access to sensitive information that may aid in further attacks SilverStripe 303 is vulnerable; other versions may also be affected <XXXX:Port>/Security/LoginForm?A ...
SilverStripe CMS version 303 suffers from an information exposure issue through query strings in GET requests ...