메뉴 건너뛰기

GREATUSER

cve

CVE-2017-18049

관리자 2018.01.25 04:00 조회 수 : 207

In the CSV export feature of SilverStripe before 3.5.6, 3.6.x before 3.6.3, and 4.x before 4.0.1, it's possible for the output to contain macros and scripts, which may be executed if imported without sanitization into common software (including Microsoft Excel). For example, the CSV data may contain untrusted user input from the "First Name" field of a user's /myprofile page.


원문출처 : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-18049
번호 제목 글쓴이 날짜 조회 수
422 CVE-2017-0075 관리자 2017.03.18 146
421 CVE-2017-0083 관리자 2017.03.18 146
420 CVE-2017-18048 관리자 2018.01.25 146
419 CVE-2017-0023 관리자 2017.03.18 147
418 CVE-2017-0121 관리자 2017.03.18 147
417 CVE-2017-5684 관리자 2017.04.04 147
416 CVE-2018-1000013 관리자 2018.01.25 147
415 CVE-2017-0053 관리자 2017.03.18 148
414 CVE-2017-2893 관리자 2017.11.09 148
413 CVE-2017-0111 관리자 2017.03.18 149
412 CVE-2017-16547 (graphicsmagick) 관리자 2017.11.09 149
411 CVE-2017-2883 관리자 2017.11.09 149
410 CVE-2016-0872 관리자 2017.11.09 149
409 CVE-2017-2740 관리자 2018.01.25 149
408 CVE-2017-9510 관리자 2017.08.27 150
위로