VYPR
Unrated severityNVD Advisory· Published Aug 26, 2012· Updated Jun 16, 2026

CVE-2010-5091

CVE-2010-5091

Description

The setName function in filesystem/File.php in SilverStripe 2.3.x before 2.3.8 and 2.4.x before 2.4.1 allows remote authenticated users with CMS author privileges to execute arbitrary PHP code by changing the extension of an uploaded file.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

15
  • cpe:2.3:a:silverstripe:silverstripe:2.3.0:*:*:*:*:*:*:*+ 14 more
    • cpe:2.3:a:silverstripe:silverstripe:2.3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:silverstripe:silverstripe:2.3.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:silverstripe:silverstripe:2.3.0:rc2:*:*:*:*:*:*
    • cpe:2.3:a:silverstripe:silverstripe:2.3.0:rc3:*:*:*:*:*:*
    • cpe:2.3:a:silverstripe:silverstripe:2.3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:silverstripe:silverstripe:2.3.1:rc1:*:*:*:*:*:*
    • cpe:2.3:a:silverstripe:silverstripe:2.3.1:rc2:*:*:*:*:*:*
    • cpe:2.3:a:silverstripe:silverstripe:2.3.2:*:*:*:*:*:*:*
    • cpe:2.3:a:silverstripe:silverstripe:2.3.3:*:*:*:*:*:*:*
    • cpe:2.3:a:silverstripe:silverstripe:2.3.4:*:*:*:*:*:*:*
    • cpe:2.3:a:silverstripe:silverstripe:2.3.5:*:*:*:*:*:*:*
    • cpe:2.3:a:silverstripe:silverstripe:2.3.6:*:*:*:*:*:*:*
    • cpe:2.3:a:silverstripe:silverstripe:2.3.7:*:*:*:*:*:*:*
    • cpe:2.3:a:silverstripe:silverstripe:2.4.0:*:*:*:*:*:*:*
    • (no CPE)range: <2.3.8, <2.4.1

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.