Exploitation Summary
EIP tracks 1 public exploit for CVE-2013-2653. PoCs published by Fara Rustein.
AI-analyzed exploit summary This is a writeup describing an information disclosure vulnerability in SilverStripe. It provides a URL template for exploiting the issue but lacks executable code or detailed technical steps.
Description
security/MemberLoginForm.php in SilverStripe 3.0.3 supports login using a GET request, which makes it easier for remote attackers to conduct phishing attacks without detection by the victim.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Fara Rustein · textwebappsphp
https://www.exploit-db.com/exploits/38689
This is a writeup describing an information disclosure vulnerability in SilverStripe. It provides a URL template for exploiting the issue but lacks executable code or detailed technical steps.
Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Theoretical
Target:
SilverStripe 3.0.3
No auth needed
Prerequisites:
Network access to the target SilverStripe instance
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (2)
Core 2
Core References
Patch x_refsource_confirm
https://github.com/chillu/silverstripe-framework/commit/3e88c98ca513880e2b43ed7f27ade17fef5d9170
Exploit mailing-list
x_refsource_bugtraq
http://seclists.org/bugtraq/2013/Aug/12
Scores
EPSS
0.0407
EPSS Percentile
89.4%
Details
CWE
CWE-20
Status
published
Products (1)
silverstripe/silverstripe
3.0.3
Published
Nov 13, 2013
Tracked Since
Feb 18, 2026