[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2537-1 typo3-src -- several

ID: oval:org.secpod.oval:def:600876Date: (C)2012-09-01   (M)2024-01-23
Class: PATCHFamily: unix




Several vulnerabilities were discovered in TYPO3, a content management system. CVE-2012-3527 An insecure call to unserialize in the help system enables arbitrary code execution by authenticated users. CVE-2012-3528 The TYPO3 backend contains several cross-site scripting vulnerabilities. CVE-2012-3529 Authenticated users who can access the configuration module can obtain the encryption key, allowing them to escalate their privileges. CVE-2012-3530 The RemoveXSS HTML sanitizer did not remove several HTML5 JavaScript, thus failing to mitigate the impact of cross-site scripting vulnerabilities.

Platform:
Debian 6.0
Product:
typo3
Reference:
DSA-2537-1
CVE-2012-3527
CVE-2012-3528
CVE-2012-3529
CVE-2012-3530
CVE-2012-3531
CVE    5
CVE-2012-3531
CVE-2012-3530
CVE-2012-3528
CVE-2012-3527
...
CPE    40
cpe:/a:typo3:typo3:4.6.9
cpe:/a:typo3:typo3:4.5.9
cpe:/a:typo3:typo3:4.6.8
cpe:/a:typo3:typo3:4.5.8
...

© SecPod Technologies