silverstripeCMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2010-4822 - Vulnerability Database

silverstripeCMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2010-4822

Medium
Reference: CVE-2010-4822
Title: silverstripeCMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Overview:

core/model/MySQLDatabase.php in SilverStripe 2.4.x before 2.4.4 when the site is running in quotlive modequot allows remote attackers to obtain the SQL queries for a page via the showqueries and ajax parameters.