Search CVE reports


Toggle filters

111 – 120 of 127 results


CVE-2009-3628

Medium priority
Ignored

The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote authenticated users to determine an encryption key via crafted input to a tt_content form element.

1 affected package

typo3-src

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
typo3-src
Show less packages

CVE-2009-0258

High priority
Ignored

The Indexed Search Engine (indexed_search) system extension in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote attackers to execute arbitrary commands via a crafted filename containing shell...

1 affected package

typo3-src

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
typo3-src
Show less packages

CVE-2009-0257

Medium priority
Ignored

Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) content...

1 affected package

typo3-src

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
typo3-src
Show less packages

CVE-2009-0256

Medium priority
Ignored

Session fixation vulnerability in the authentication library in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote attackers to hijack web sessions via unspecified vectors related to (1) frontend...

1 affected package

typo3-src

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
typo3-src
Show less packages

CVE-2009-0255

Medium priority
Ignored

The System extension Install tool in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 creates the encryption key with an insufficiently random seed, which makes it easier for attackers to crack the key.

1 affected package

typo3-src

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
typo3-src
Show less packages

CVE-2008-6594

Medium priority
Ignored

SQL injection vulnerability in the cm_rdfexport extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

1 affected package

typo3-src

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
typo3-src
Show less packages

CVE-2008-5656

Low priority
Ignored

Cross-site scripting (XSS) vulnerability in the frontend plugin for the felogin system extension in TYPO3 4.2.0, 4.2.1 and 4.2.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

1 affected package

typo3-src

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
typo3-src
Show less packages

CVE-2008-5644

Low priority
Not affected

Cross-site scripting (XSS) vulnerability in the file backend module in TYPO3 4.2.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

1 affected package

typo3-src

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
typo3-src
Show less packages

CVE-2008-4905

Low priority
Ignored

Typo 5.1.3 and earlier uses a hard-coded salt for calculating password hashes, which makes it easier for attackers to guess passwords via a brute force attack.

1 affected package

typo3-src

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
typo3-src
Show less packages

CVE-2008-4904

Medium priority
Ignored

SQL injection vulnerability in the “Manage pages” feature (admin/pages) in Typo 5.1.3 and earlier allows remote authenticated users with “blog publisher” rights to execute arbitrary SQL commands via the search[published_at] parameter.

1 affected package

typo3-src

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
typo3-src
Show less packages