Show plain JSON{"containers": {"cna": {"affected": [{"product": "n/a", "vendor": "n/a", "versions": [{"status": "affected", "version": "n/a"}]}], "descriptions": [{"lang": "en", "value": "The setName function in filesystem/File.php in SilverStripe 2.3.x before 2.3.8 and 2.4.x before 2.4.1 allows remote authenticated users with CMS author privileges to execute arbitrary PHP code by changing the extension of an uploaded file."}], "problemTypes": [{"descriptions": [{"description": "n/a", "lang": "en", "type": "text"}]}], "providerMetadata": {"dateUpdated": "2012-08-26T18:00:00Z", "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749", "shortName": "redhat"}, "references": [{"name": "[oss-security] 20120501 Re: CVE-request: SilverStripe before 2.4.4", "tags": ["mailing-list", "x_refsource_MLIST"], "url": "http://www.openwall.com/lists/oss-security/2012/05/01/3"}, {"tags": ["x_refsource_MISC"], "url": "http://open.silverstripe.org/ticket/5693"}, {"name": "[oss-security] 20120430 CVE-request: SilverStripe before 2.4.4", "tags": ["mailing-list", "x_refsource_MLIST"], "url": "http://www.openwall.com/lists/oss-security/2012/04/30/1"}, {"name": "[oss-security] 20120430 Re: CVE-request: SilverStripe before 2.4.4", "tags": ["mailing-list", "x_refsource_MLIST"], "url": "http://www.openwall.com/lists/oss-security/2012/04/30/3"}, {"tags": ["x_refsource_MISC"], "url": "http://dl.packetstormsecurity.net/1006-exploits/silverstripe-shell.txt"}, {"tags": ["x_refsource_CONFIRM"], "url": "http://doc.silverstripe.org/sapphire/en/trunk/changelogs//2.4.1"}, {"tags": ["x_refsource_CONFIRM"], "url": "http://open.silverstripe.org/changeset/107273"}, {"tags": ["x_refsource_CONFIRM"], "url": "http://doc.silverstripe.org/sapphire/en/trunk/changelogs//2.3.8"}], "x_legacyV4Record": {"CVE_data_meta": {"ASSIGNER": "secalert@redhat.com", "ID": "CVE-2010-5091", "STATE": "PUBLIC"}, "affects": {"vendor": {"vendor_data": [{"product": {"product_data": [{"product_name": "n/a", "version": {"version_data": [{"version_value": "n/a"}]}}]}, "vendor_name": "n/a"}]}}, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": {"description_data": [{"lang": "eng", "value": "The setName function in filesystem/File.php in SilverStripe 2.3.x before 2.3.8 and 2.4.x before 2.4.1 allows remote authenticated users with CMS author privileges to execute arbitrary PHP code by changing the extension of an uploaded file."}]}, "problemtype": {"problemtype_data": [{"description": [{"lang": "eng", "value": "n/a"}]}]}, "references": {"reference_data": [{"name": "[oss-security] 20120501 Re: CVE-request: SilverStripe before 2.4.4", "refsource": "MLIST", "url": "http://www.openwall.com/lists/oss-security/2012/05/01/3"}, {"name": "http://open.silverstripe.org/ticket/5693", "refsource": "MISC", "url": "http://open.silverstripe.org/ticket/5693"}, {"name": "[oss-security] 20120430 CVE-request: SilverStripe before 2.4.4", "refsource": "MLIST", "url": "http://www.openwall.com/lists/oss-security/2012/04/30/1"}, {"name": "[oss-security] 20120430 Re: CVE-request: SilverStripe before 2.4.4", "refsource": "MLIST", "url": "http://www.openwall.com/lists/oss-security/2012/04/30/3"}, {"name": "http://dl.packetstormsecurity.net/1006-exploits/silverstripe-shell.txt", "refsource": "MISC", "url": "http://dl.packetstormsecurity.net/1006-exploits/silverstripe-shell.txt"}, {"name": "http://doc.silverstripe.org/sapphire/en/trunk/changelogs//2.4.1", "refsource": "CONFIRM", "url": "http://doc.silverstripe.org/sapphire/en/trunk/changelogs//2.4.1"}, {"name": "http://open.silverstripe.org/changeset/107273", "refsource": "CONFIRM", "url": "http://open.silverstripe.org/changeset/107273"}, {"name": "http://doc.silverstripe.org/sapphire/en/trunk/changelogs//2.3.8", "refsource": "CONFIRM", "url": "http://doc.silverstripe.org/sapphire/en/trunk/changelogs//2.3.8"}]}}}, "adp": [{"providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-07T04:09:38.807Z"}, "title": "CVE Program Container", "references": [{"name": "[oss-security] 20120501 Re: CVE-request: SilverStripe before 2.4.4", "tags": ["mailing-list", "x_refsource_MLIST", "x_transferred"], "url": "http://www.openwall.com/lists/oss-security/2012/05/01/3"}, {"tags": ["x_refsource_MISC", "x_transferred"], "url": "http://open.silverstripe.org/ticket/5693"}, {"name": "[oss-security] 20120430 CVE-request: SilverStripe before 2.4.4", "tags": ["mailing-list", "x_refsource_MLIST", "x_transferred"], "url": "http://www.openwall.com/lists/oss-security/2012/04/30/1"}, {"name": "[oss-security] 20120430 Re: CVE-request: SilverStripe before 2.4.4", "tags": ["mailing-list", "x_refsource_MLIST", "x_transferred"], "url": "http://www.openwall.com/lists/oss-security/2012/04/30/3"}, {"tags": ["x_refsource_MISC", "x_transferred"], "url": "http://dl.packetstormsecurity.net/1006-exploits/silverstripe-shell.txt"}, {"tags": ["x_refsource_CONFIRM", "x_transferred"], "url": "http://doc.silverstripe.org/sapphire/en/trunk/changelogs//2.4.1"}, {"tags": ["x_refsource_CONFIRM", "x_transferred"], "url": "http://open.silverstripe.org/changeset/107273"}, {"tags": ["x_refsource_CONFIRM", "x_transferred"], "url": "http://doc.silverstripe.org/sapphire/en/trunk/changelogs//2.3.8"}]}]}, "cveMetadata": {"assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749", "assignerShortName": "redhat", "cveId": "CVE-2010-5091", "datePublished": "2012-08-26T18:00:00Z", "dateReserved": "2012-04-30T00:00:00Z", "dateUpdated": "2024-09-16T23:20:47.546Z", "state": "PUBLISHED"}, "dataType": "CVE_RECORD", "dataVersion": "5.1"}