메뉴 건너뛰기

GREATUSER

cve

CVE-2017-18049

관리자 2018.01.25 04:00 조회 수 : 207

In the CSV export feature of SilverStripe before 3.5.6, 3.6.x before 3.6.3, and 4.x before 4.0.1, it's possible for the output to contain macros and scripts, which may be executed if imported without sanitization into common software (including Microsoft Excel). For example, the CSV data may contain untrusted user input from the "First Name" field of a user's /myprofile page.


원문출처 : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-18049
번호 제목 글쓴이 날짜 조회 수
542 CVE-2017-9650 관리자 2017.08.27 227
541 CVE-2017-0034 관리자 2017.03.18 227
540 CVE-2018-6022 관리자 2018.01.25 226
539 CVE-2017-0035 관리자 2017.03.18 226
538 CVE-2017-15093 관리자 2018.01.25 225
537 CVE-2018-5784 관리자 2018.01.25 225
536 CVE-2016-3221 관리자 2016.06.17 225
535 CVE-2017-12703 관리자 2017.08.27 223
534 CVE-2017-5686 관리자 2017.04.04 223
533 CVE-2018-6013 관리자 2018.01.25 222
532 CVE-2017-7930 관리자 2017.08.27 222
531 CVE-2017-0097 관리자 2017.03.18 222
530 CVE-2016-0200 관리자 2016.06.17 222
529 CVE-2017-7934 관리자 2017.08.27 221
528 CVE-2017-12097 관리자 2018.01.25 220
위로