Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2010-4823

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2010-4823
Last Modified 18 Sep 2012 12:00:00
Published 17 Sep 2012 01:55:02
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2010-4823

Summary

Cross-site scripting (XSS) vulnerability in the httpError method in sapphire/core/control/RequestHandler.php in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4, when custom error handling is not used, allows remote attackers to inject arbitrary web script or HTML via "missing URL actions."

Vulnerable Systems

Application

  • Silverstripe 2.3.0

  • Silverstripe 2.3.1

  • Silverstripe 2.3.2

  • Silverstripe 2.3.3

  • Silverstripe 2.3.4

  • Silverstripe 2.3.5

  • Silverstripe 2.3.6

  • Silverstripe 2.3.7

  • Silverstripe 2.3.8

  • Silverstripe 2.3.9

  • Silverstripe 2.4.0

  • Silverstripe 2.4.1

  • Silverstripe 2.4.2

  • Silverstripe 2.4.3


References

XF - silverstripe-requesthandler-xss(63988)

BID - 45367

OSVDB - 69886

MLIST - [oss-security] 20120501 Re: CVE-request: SilverStripe before 2.4.4

MLIST - [oss-security] 20120430 Re: CVE-request: SilverStripe before 2.4.4

MLIST - [oss-security] 20120430 CVE-request: SilverStripe before 2.4.4

MLIST - [oss-security] 20110104 CVE request: silverstripe before 2.4.4

SECUNIA - 42346

CONFIRM - http://open.silverstripe.org/changeset/114444

CONFIRM - http://doc.silverstripe.org/framework/en/trunk/changelogs//2.4.4


Last Updated: 27 May 2016 11:00:43