4

CVE-2009-1264

Frontend User Registration (sr_feuser_register) extension 2.5.20 and earlier for TYPO3 does not properly verify access rights, which allows remote authenticated users to obtain sensitive information such as passwords via unknown attack vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Stanislas RollandSr Feuser Register Version <= 2.5.20
   Typo3Typo3
Stanislas RollandSr Feuser Register Version1.4
   Typo3Typo3
Stanislas RollandSr Feuser Register Version1.6
   Typo3Typo3
Stanislas RollandSr Feuser Register Version2.2.1
   Typo3Typo3
Stanislas RollandSr Feuser Register Version2.2.7
   Typo3Typo3
Stanislas RollandSr Feuser Register Version2.2.8
   Typo3Typo3
Stanislas RollandSr Feuser Register Version2.3
   Typo3Typo3
Stanislas RollandSr Feuser Register Version2.3.6
   Typo3Typo3
Stanislas RollandSr Feuser Register Version2.4
   Typo3Typo3
Stanislas RollandSr Feuser Register Version2.5
   Typo3Typo3
Stanislas RollandSr Feuser Register Version2.5.10
   Typo3Typo3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.15% 0.628
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://osvdb.org/53278
http://secunia.com/advisories/34586
Vendor Advisory
http://typo3.org/extensions/repository/view/sr_feuser_register/2.5.21/
Patch
Vendor Advisory
http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-004/
Patch
Vendor Advisory
http://www.securityfocus.com/bid/34374
Patch
http://www.vupen.com/english/advisories/2009/0938
Patch
Vendor Advisory