Required CVE Record Information
Description
Cross-site scripting (XSS) vulnerability in the process function in SSViewer.php in SilverStripe before 2.3.13 and 2.4.x before 2.4.6 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING to template placeholders, as demonstrated by a request to (1) admin/reports/, (2) admin/comments/, (3) admin/, (4) admin/show/, (5) admin/assets/, and (6) admin/security/.
References 9 Total
- securityfocus.com: 20111008 SilverStripe 2.4.5 Multiple backend Cross-site scripting vulnerabilities mailing-list
- http://doc.silverstripe.org/sapphire/en/trunk/changelogs/2.4.6
- http://doc.silverstripe.org/sapphire/en/trunk/changelogs/2.3.12
- osvdb.org: 76258 vdb-entry
- https://github.com/silverstripe/sapphire/commit/bdd6391
- secunia.com: 46390 third-party-advisory
- https://github.com/silverstripe/sapphire/commit/52a895f
- https://github.com/silverstripe/sapphire/commit/16c3235
- http://www.rul3z.de/advisories/SSCHADV2011-024.txt
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 9 Total
- securityfocus.com: 20111008 SilverStripe 2.4.5 Multiple backend Cross-site scripting vulnerabilities mailing-listx_transferred
- http://doc.silverstripe.org/sapphire/en/trunk/changelogs/2.4.6 x_transferred
- http://doc.silverstripe.org/sapphire/en/trunk/changelogs/2.3.12 x_transferred
- osvdb.org: 76258 vdb-entryx_transferred
- https://github.com/silverstripe/sapphire/commit/bdd6391 x_transferred
- secunia.com: 46390 third-party-advisoryx_transferred
- https://github.com/silverstripe/sapphire/commit/52a895f x_transferred
- https://github.com/silverstripe/sapphire/commit/16c3235 x_transferred
- http://www.rul3z.de/advisories/SSCHADV2011-024.txt x_transferred