CVE-2010-4822 Information

Description

core/model/MySQLDatabase.php in SilverStripe 2.4.x before 2.4.4 when the site is running in \live mode\ allows remote attackers to obtain the SQL queries for a page via the showqueries and ajax parameters.

Reference

http://doc.silverstripe.org/framework/en/trunk/changelogs//2.4.4 http://open.silverstripe.org/changeset/114783 http://secunia.com/advisories/42346 http://www.openwall.com/lists/oss-security/2011/01/03/12 http://www.openwall.com/lists/oss-security/2012/04/30/1 http://www.openwall.com/lists/oss-security/2012/04/30/3 http://www.openwall.com/lists/oss-security/2012/05/01/3 http://www.osvdb.org/69885

Share on: