Description
Cross-site scripting (XSS) vulnerability in the process function in SSViewer.php in SilverStripe before 2.3.13 and 2.4.x before 2.4.6 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING to template placeholders, as demonstrated by a request to (1) admin/reports/, (2) admin/comments/, (3) admin/, (4) admin/show/, (5) admin/assets/, and (6) admin/security/.
Exploits
362262011-10-11webappsPHP
SilverStripe CMS 2.4.5 - Multiple Cross-Site Scripting Vulnerabilities
By Stefan Schurtz
References
secalert@redhat.com
http://doc.silverstripe.org/sapphire/en/trunk/changelogs/2.3.12secalert@redhat.com
http://doc.silverstripe.org/sapphire/en/trunk/changelogs/2.4.6secalert@redhat.com
http://osvdb.org/76258secalert@redhat.com
http://secunia.com/advisories/46390secalert@redhat.com
http://www.rul3z.de/advisories/SSCHADV2011-024.txtsecalert@redhat.com
http://www.securityfocus.com/archive/1/520050/100/0/threadedsecalert@redhat.com
https://github.com/silverstripe/sapphire/commit/16c3235secalert@redhat.com
https://github.com/silverstripe/sapphire/commit/52a895fsecalert@redhat.com
https://github.com/silverstripe/sapphire/commit/bdd6391af854a3a-2127-422b-91ae-364da2661108
http://doc.silverstripe.org/sapphire/en/trunk/changelogs/2.3.12af854a3a-2127-422b-91ae-364da2661108
http://doc.silverstripe.org/sapphire/en/trunk/changelogs/2.4.6af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/76258af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/46390af854a3a-2127-422b-91ae-364da2661108
http://www.rul3z.de/advisories/SSCHADV2011-024.txtaf854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/520050/100/0/threadedaf854a3a-2127-422b-91ae-364da2661108
https://github.com/silverstripe/sapphire/commit/16c3235af854a3a-2127-422b-91ae-364da2661108
https://github.com/silverstripe/sapphire/commit/52a895faf854a3a-2127-422b-91ae-364da2661108
https://github.com/silverstripe/sapphire/commit/bdd6391