CVE-2010-4824

SilverStripe <2.3.10-2.4.4 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in the augmentSQL method in core/model/Translatable.php in SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4, when the Translatable extension is enabled, allows remote attackers to execute arbitrary SQL commands via the locale parameter.

References (12)

Core 12
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/63989
Exploit, Patch x_refsource_confirm
http://open.silverstripe.org/changeset/114517
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/05/01/3
Exploit, Patch x_refsource_confirm
http://open.silverstripe.org/changeset/114515
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/45367
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42346
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/04/30/1
Patch mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/04/30/3
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/69884
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/01/03/12

Scores

EPSS 0.0256
EPSS Percentile 83.4%

Details

CWE
CWE-89
Status published
Products (14)
silverstripe/silverstripe 2.3.0
silverstripe/silverstripe 2.3.1
silverstripe/silverstripe 2.3.2
silverstripe/silverstripe 2.3.3
silverstripe/silverstripe 2.3.4
silverstripe/silverstripe 2.3.5
silverstripe/silverstripe 2.3.6
silverstripe/silverstripe 2.3.7
silverstripe/silverstripe 2.3.8
silverstripe/silverstripe 2.3.9
... and 4 more
Published Sep 17, 2012
Tracked Since Feb 18, 2026