Typo3

Typo3

218 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.39%
  • Veröffentlicht 21.05.2012 20:55:16
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in the FORM content object in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

  • EPSS 0.35%
  • Veröffentlicht 21.05.2012 20:55:16
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple cross-site scripting (XSS) vulnerabilities in the Install Tool in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

  • EPSS 0.41%
  • Veröffentlicht 21.05.2012 20:55:16
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Directory traversal vulnerability in the TypoScript setup in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 allows remote authenticated administrators to read arbitrary files via unspecified vectors related to the "file inclusi...

  • EPSS 2.94%
  • Veröffentlicht 18.02.2012 00:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

PHP remote file inclusion vulnerability in Classes/Controller/AbstractController.php in the workspaces system extension in TYPO3 4.5.x before 4.5.9, 4.6.x before 4.6.2, and development versions of 4.7 allows remote attackers to execute arbitrary PHP ...

  • EPSS 34.73%
  • Veröffentlicht 25.10.2010 20:01:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The jumpUrl (aka access tracking) implementation in tslib/class.tslib_fe.php in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 does not properly compare certain hash values during access-control decisions, which allows remote a...

  • EPSS 0.3%
  • Veröffentlicht 25.10.2010 20:01:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the RemoveXSS function, and allow re...

  • EPSS 0.41%
  • Veröffentlicht 25.10.2010 20:01:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The be_user_creation task in TYPO3 4.2.x before 4.2.15 and 4.3.x before 4.3.7 allows remote authenticated users to gain privileges via a crafted POST request that creates a user account with arbitrary group memberships.

  • EPSS 0.54%
  • Veröffentlicht 25.10.2010 20:01:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The t3lib_div::validEmail function in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 does not properly restrict input to filter_var FILTER_VALIDATE_EMAIL operations in PHP, which allows remote attackers to cause a denial of ser...

  • EPSS 0.19%
  • Veröffentlicht 25.10.2010 20:01:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Unspecified vulnerability in the Extension Manager in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 allows remote authenticated administrators to read and possibly modify arbitrary files via a crafted parameter, a different vu...

Exploit
  • EPSS 0.72%
  • Veröffentlicht 11.05.2010 12:02:08
  • Zuletzt bearbeitet 11.04.2025 00:51:21

SQL injection vulnerability in index.php in TYPO3 4.0 allows remote attackers to execute arbitrary SQL commands via the showUid parameter. NOTE: the TYPO3 Security Team disputes this report, stating that "there is no such vulnerability... The showUid...