CVE-2010-1593
Summary
Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via (1) the CommenterURL parameter to PostCommentForm, and in the Forum module before 0.2.5 in SilverStripe before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via (2) the Search parameter to forums/search (aka the search script).
Impact & exploitability
AV:N/AC:M/Au:N/C:N/I:P/A:N
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Official patch: http://groups.google.com/group/silverstripe-announce/browse_thread/thread/f51749342eee9456 ↗
Additional information
- NVD record
- http://groups.google.com/group/silverstripe-announce/browse_thread/thread/f51749342eee9456Patch
- http://open.silverstripe.org/changeset/97074Patch
- http://secunia.com/advisories/38290Advisory
- http://secunia.com/advisories/38347Advisory
- http://open.silverstripe.org/wiki/ChangeLog/2.3.5
- http://osvdb.org/61921
- http://osvdb.org/61923
- http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0450.htmlExploit