Vulnerability index

Browse CVEs

67 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Silverstripe MEDIUM 5.0
CVE-2010-5087

SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism …

Patch available
Fix from $1,600 2012-08-26
Silverstripe MEDIUM 5.0
CVE-2010-5093

Member_ProfileForm in security/Member.php in SilverStripe 2.3.x before 2.3.7 allows remote attackers to hijack user accounts by saving data using the…

Patch available
Fix from $1,600 2012-08-26
Silverstripe MEDIUM 5.0
CVE-2010-5094

The deleteinstallfiles function in control/ContentController.php in SilverStripe 2.3.x before 2.3.7 does not require ADMIN permissions, which allows …

Mitigation only
Fix from $1,600 2012-08-26
Silverstripe MEDIUM 5.0
CVE-2010-5188

SilverStripe 2.3.x before 2.3.6 allows remote attackers to obtain sensitive information via the (1) debug_memory parameter to core/control/Director.p…

Patch available
Fix from $1,600 2012-08-26
Silverstripe HIGH 7.5
CVE-2008-6753

SQL injection vulnerability in SilverStripe before 2.2.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to…

Fix: after 2.2.1
Fix from $1,950 2009-04-27
Silverstripe HIGH 7.5
CVE-2009-1433

SQL injection vulnerability in File::find (filesystem/File.php) in SilverStripe before 2.3.1 allows remote attackers to execute arbitrary SQL command…

Fix: after 2.3.1
Fix from $1,950 2009-04-24
Silverstripe HIGH 10.0
CVE-2007-2321

Unspecified vulnerability in the search functionality in SilverStripe 2.0.0 has unknown impact and attack vectors.

Patch available
Fix from $1,950 2007-04-27