메뉴 건너뛰기

GREATUSER

cve

CVE-2017-18049

관리자 2018.01.25 04:00 조회 수 : 207

In the CSV export feature of SilverStripe before 3.5.6, 3.6.x before 3.6.3, and 4.x before 4.0.1, it's possible for the output to contain macros and scripts, which may be executed if imported without sanitization into common software (including Microsoft Excel). For example, the CSV data may contain untrusted user input from the "First Name" field of a user's /myprofile page.


원문출처 : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-18049
번호 제목 글쓴이 날짜 조회 수
422 CVE-2017-16561 관리자 2017.11.09 195
421 CVE-2017-16642 관리자 2017.11.09 164
420 CVE-2008-7319 관리자 2017.11.09 167
419 CVE-2016-0872 관리자 2017.11.09 149
418 CVE-2017-16641 관리자 2017.11.09 121
417 CVE-2017-2922 관리자 2017.11.09 137
416 CVE-2017-2916 관리자 2017.11.09 169
415 CVE-2017-2921 관리자 2017.11.09 167
414 CVE-2017-2917 관리자 2017.11.09 161
413 CVE-2017-2915 관리자 2017.11.09 152
412 CVE-2017-2914 관리자 2017.11.09 232
411 CVE-2017-2913 관리자 2017.11.09 160
410 CVE-2017-12083 관리자 2017.11.09 165
409 CVE-2017-2864 관리자 2017.11.09 150
408 CVE-2017-2894 관리자 2017.11.09 176
위로