CVE-2010-1593
N/A
N/A
Summary
Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via (1) the CommenterURL parameter to PostCommentForm, and in the Forum module before 0.2.5 in SilverStripe before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via (2) the Search parameter to forums/search (aka the search script).
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.silverstripe.org/security-releases/
- http://osvdb.org/61921
- http://secunia.com/advisories/38347
- http://osvdb.org/61923
- http://www.securityfocus.com/archive/1/509139/100/0/threaded
- http://open.silverstripe.org/wiki/ChangeLog/2.3.5
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55838
- http://www.securityfocus.com/bid/37923
- http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0450.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55839
- http://groups.google.com/group/silverstripe-announce/browse_thread/thread/f51749342eee9456
- http://open.silverstripe.org/changeset/97074
- http://secunia.com/advisories/38290
References
- http://www.silverstripe.org/security-releases/
- http://osvdb.org/61921
- http://secunia.com/advisories/38347
- http://osvdb.org/61923
- http://www.securityfocus.com/archive/1/509139/100/0/threaded
- http://open.silverstripe.org/wiki/ChangeLog/2.3.5
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55838
- http://www.securityfocus.com/bid/37923
- http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0450.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55839
- http://groups.google.com/group/silverstripe-announce/browse_thread/thread/f51749342eee9456
- http://open.silverstripe.org/changeset/97074
- http://secunia.com/advisories/38290
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.