Show filters
297 Total Results
Displaying 181-190 of 297
Sort by:
Attacker Value
Unknown
CVE-2012-1074
Disclosure Date: February 14, 2012 (last updated October 04, 2023)
SQL injection vulnerability in the White Papers (mm_whtppr) extension 0.0.4 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-1084
Disclosure Date: February 14, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the BE User Switch (beuserswitch) extension 0.0.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2010-3714
Disclosure Date: October 25, 2010 (last updated October 04, 2023)
The jumpUrl (aka access tracking) implementation in tslib/class.tslib_fe.php in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 does not properly compare certain hash values during access-control decisions, which allows remote attackers to read arbitrary files via unspecified vectors.
0
Attacker Value
Unknown
CVE-2010-3716
Disclosure Date: October 25, 2010 (last updated October 04, 2023)
The be_user_creation task in TYPO3 4.2.x before 4.2.15 and 4.3.x before 4.3.7 allows remote authenticated users to gain privileges via a crafted POST request that creates a user account with arbitrary group memberships.
0
Attacker Value
Unknown
CVE-2010-3715
Disclosure Date: October 25, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the RemoveXSS function, and allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (2) the backend.
0
Attacker Value
Unknown
CVE-2010-3717
Disclosure Date: October 25, 2010 (last updated October 04, 2023)
The t3lib_div::validEmail function in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 does not properly restrict input to filter_var FILTER_VALIDATE_EMAIL operations in PHP, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a long e-mail address string, a related issue to CVE-2010-3710.
0
Attacker Value
Unknown
CVE-2010-4068
Disclosure Date: October 25, 2010 (last updated October 04, 2023)
Unspecified vulnerability in the Extension Manager in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 allows remote authenticated administrators to read and possibly modify arbitrary files via a crafted parameter, a different vulnerability than CVE-2010-3714.
0
Attacker Value
Unknown
CVE-2009-4970
Disclosure Date: July 28, 2010 (last updated October 04, 2023)
SQL injection vulnerability in the t3m_affiliate extension 0.5.0 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2009-4969
Disclosure Date: July 28, 2010 (last updated October 04, 2023)
SQL injection vulnerability in the Solidbase Bannermanagement (SBbanner) extension 1.0.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2009-4963
Disclosure Date: July 28, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Commerce extension before 0.9.9 for TYPO3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
0