[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2445-1 typo3 -- several

ID: oval:org.secpod.oval:def:600771Date: (C)2012-04-03   (M)2022-10-10
Class: PATCHFamily: unix




Several remote vulnerabilities have been discovered in the TYPO3 web content management framework: CVE-2012-1606 Failing to properly HTML-encode user input in several places, the TYPO3 backend is susceptible to Cross-Site Scripting. A valid backend user is required to exploit these vulnerabilities. CVE-2012-1607 Accessing a CLI Script directly with a browser may disclose the database name used for the TYPO3 installation. CVE-2012-1608 By not removing non printable characters, the API method t3lib_div::RemoveXSS fails to filter specially crafted HTML injections, thus is susceptible to Cross-Site Scripting.

Platform:
Debian 6.0
Product:
typo3
Reference:
DSA-2445-1
CVE-2012-1606
CVE-2012-1607
CVE-2012-1608
CVE    3
CVE-2012-1608
CVE-2012-1606
CVE-2012-1607
CPE    42
cpe:/a:typo3:typo3:4.5.9
cpe:/a:typo3:typo3:4.4.9
cpe:/a:typo3:typo3:4.5.8
cpe:/a:typo3:typo3:4.4.8
...

© SecPod Technologies