Описание
SQL injection vulnerability in the addslashes method in SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6, when connected to a MySQL database using far east character encodings, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
SQL injection vulnerability in the addslashes method in SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6, when connected to a MySQL database using far east character encodings, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2011-4959
- https://github.com/silverstripe/sapphire/commit/73cca09
- https://github.com/silverstripe/sapphire/commit/ca78784
- https://github.com/silverstripe/silverstripe-cms/commit/b5ea2f6
- http://doc.silverstripe.org/framework/en/trunk/changelogs/2.3.12
- http://doc.silverstripe.org/framework/en/trunk/changelogs/2.4.6
- http://www.openwall.com/lists/oss-security/2012/04/30/1
- http://www.openwall.com/lists/oss-security/2012/04/30/3
Связанные уязвимости
SQL injection vulnerability in the addslashes method in SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6, when connected to a MySQL database using far east character encodings, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
SQL injection vulnerability in the addslashes method in SilverStripe 2 ...