NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 16326 | CVE-2010-5091 | The setName function in filesystem/File.php in SilverStripe 2.3.x before 2.3.8 and 2.4.x before 2.4.1 allows remote authenticated users with CMS author privileges to execute arbitrary PHP code by changing the extension of an uploaded file. | 2 | 6 | Medium | 2017-01-18 | 2012-08-27 | View | |
| 16327 | CVE-2010-5092 | The Add Member dialog in the Security admin page in SilverStripe 2.4.0 saves user passwords in plaintext, which allows local users to obtain sensitive information by reading a database. | 2 | 1.9 | Low | 2017-01-18 | 2012-08-27 | View | |
| 16328 | CVE-2010-5093 | Member_ProfileForm in security/Member.php in SilverStripe 2.3.x before 2.3.7 allows remote attackers to hijack user accounts by saving data using the email address (ID) of another user. | 2 | 5 | Medium | 2017-01-18 | 2012-08-27 | View | |
| 16329 | CVE-2010-5094 | The deleteinstallfiles function in control/ContentController.php in SilverStripe 2.3.x before 2.3.7 does not require ADMIN permissions, which allows remote attackers to delete index.php and "disrupt mod_rewrite-less URL routing." | 2 | 5 | Medium | 2017-01-18 | 2012-08-27 | View | |
| 16330 | CVE-2010-5095 | Cross-site scripting (XSS) vulnerability in SilverStripe 2.3.x before 2.3.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to DataObjectSet pagination. | 2 | 4.3 | Medium | 2017-01-18 | 2012-08-27 | View |
Page 3266 of 17672, showing 5 records out of 88360 total, starting on record 16326, ending on 16330