CVE-2013-1842
- EPSS 3.33%
- Veröffentlicht 20.03.2013 15:55:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
SQL injection vulnerability in the Extbase Framework in TYPO3 4.5.x before 4.5.24, 4.6.x before 4.6.17, 4.7.x before 4.7.9, and 6.0.x before 6.0.3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to "the Quer...
CVE-2012-3529
- EPSS 0.37%
- Veröffentlicht 05.09.2012 23:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The configuration module in the backend in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote authenticated backend users to obtain the encryption key via unspecified vectors.
CVE-2012-3530
- EPSS 0.57%
- Veröffentlicht 05.09.2012 23:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Incomplete blacklist vulnerability in the t3lib_div::quoteJSvalue API function in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote attackers to conduct cross-site scripting (XSS) attacks via certain HTML5 JavaScript...
CVE-2012-3531
- EPSS 0.25%
- Veröffentlicht 05.09.2012 23:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the Install Tool in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2012-3527
- EPSS 2.07%
- Veröffentlicht 05.09.2012 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
view_help.php in the backend help system in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote authenticated backend users to unserialize arbitrary objects and possibly execute arbitrary PHP code via an unspecified pa...
CVE-2012-3528
- EPSS 0.52%
- Veröffentlicht 05.09.2012 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in the backend in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allow remote authenticated backend users to inject arbitrary web script or HTML via unspecified vectors.
- EPSS 0.94%
- Veröffentlicht 04.09.2012 20:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Extbase Framework in TYPO3 4.6.x through 4.6.6, 4.7, and 6.0 unserializes untrusted data, which allows remote attackers to unserialize arbitrary objects and possibly execute arbitrary code via vectors related to "a missing signature (HMAC) for a ...
CVE-2012-1606
- EPSS 0.29%
- Veröffentlicht 04.09.2012 20:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in the Backend component in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allow remote authenticated backend users to inject arbitrary web script or HTML via un...
- EPSS 0.7%
- Veröffentlicht 04.09.2012 20:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Command Line Interface (CLI) script in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attackers to obtain the database name via a direct request.
- EPSS 0.68%
- Veröffentlicht 04.09.2012 20:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The t3lib_div::RemoveXSS API method in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and inject arbitrary web script or HTML v...