The setName function in filesystem/File.php in SilverStripe 2.3.x before 2.3.8 and 2.4.x before 2.4.1 allows remote authenticated users with CMS author privileges to execute arbitrary PHP code by changing the extension of an uploaded file.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2022-10-03T16:21:03
Updated: 2022-10-03T16:21:03
Reserved: 2022-10-03T00:00:00
Link: CVE-2010-5091
JSON object: View
NVD Information
Status : Analyzed
Published: 2012-08-26T18:55:01.310
Modified: 2012-08-27T04:00:00.000
Link: CVE-2010-5091
JSON object: View
Redhat Information
No data.
CWE