Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2011-4962

Опубликовано: 17 сент. 2012
Источник: debian

Описание

code/sitefeatures/PageCommentInterface.php in SilverStripe 2.4.x before 2.4.6 might allow remote attackers to execute arbitrary code via a crafted cookie in a user comment submission, which is not properly handled when it is deserialized.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
silverstripeitppackage

Примечания

  • http://seclists.org/oss-sec/2012/q2/209

Связанные уязвимости

nvd
больше 13 лет назад

code/sitefeatures/PageCommentInterface.php in SilverStripe 2.4.x before 2.4.6 might allow remote attackers to execute arbitrary code via a crafted cookie in a user comment submission, which is not properly handled when it is deserialized.

github
больше 3 лет назад

Silverstripe CMS Arbitrary Code Execution