Security Advisory

CVE-2010-5094

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2012-08-26 18:00:00
Last updated 2024-09-17 00:11:21
Assigner redhat
State PUBLISHED

Description

The deleteinstallfiles function in control/ContentController.php in SilverStripe 2.3.x before 2.3.7 does not require ADMIN permissions, which allows remote attackers to delete index.php and "disrupt mod_rewrite-less URL routing."