NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
16326  CVE-2010-5091  The setName function in filesystem/File.php in SilverStripe 2.3.x before 2.3.8 and 2.4.x before 2.4.1 allows remote authenticated users with CMS author privileges to execute arbitrary PHP code by changing the extension of an uploaded file.    Medium  2017-01-18  2012-08-27  View
16327  CVE-2010-5092  The Add Member dialog in the Security admin page in SilverStripe 2.4.0 saves user passwords in plaintext, which allows local users to obtain sensitive information by reading a database.    1.9  Low  2017-01-18  2012-08-27  View
16328  CVE-2010-5093  Member_ProfileForm in security/Member.php in SilverStripe 2.3.x before 2.3.7 allows remote attackers to hijack user accounts by saving data using the email address (ID) of another user.    Medium  2017-01-18  2012-08-27  View
16329  CVE-2010-5094  The deleteinstallfiles function in control/ContentController.php in SilverStripe 2.3.x before 2.3.7 does not require ADMIN permissions, which allows remote attackers to delete index.php and "disrupt mod_rewrite-less URL routing."    Medium  2017-01-18  2012-08-27  View
16330  CVE-2010-5095  Cross-site scripting (XSS) vulnerability in SilverStripe 2.3.x before 2.3.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to DataObjectSet pagination.    4.3  Medium  2017-01-18  2012-08-27  View

Page 3266 of 17672, showing 5 records out of 88360 total, starting on record 16326, ending on 16330

Actions