[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2646-1 typo3-src -- several

ID: oval:org.secpod.oval:def:600993Date: (C)2013-03-19   (M)2022-10-10
Class: PATCHFamily: unix




Typo3, a PHP-based content management system, was found vulnerable to several vulnerabilities. CVE-2013-1842 Helmut Hummel and Markus Opahle discovered that the Extbase database layer was not correctly sanitizing user input when using the Query object model. This can lead to SQL injection by a malicious user inputing crafted relation values. CVE-2013-1843 Missing user input validation in the access tracking mechanism could lead to arbitrary URL redirection. Note: the fix will break already published links

Platform:
Debian 6.0
Product:
typo3
Reference:
DSA-2646-1
CVE-2013-1842
CVE-2013-1843
CVE    2
CVE-2013-1842
CVE-2013-1843
CPE    56
cpe:/a:typo3:typo3:4.6.9
cpe:/a:typo3:typo3:4.6.8
cpe:/a:typo3:typo3:4.6.7
cpe:/a:typo3:typo3:4.6.6
...

© SecPod Technologies