Skip to main content

Vendor archive

typo3 CVEs

Beta · best-effort

518 CVEs tagged to vendor typo317 Critical, 202 High, 269 Medium, 30 Low, 0 Unrated.

CVE-2009-4158

Published Dec 2, 2009

SQL injection vulnerability in the Calendar Base (cal) extension before 1.2.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-3636

Published Nov 2, 2009

Cross-site scripting (XSS) vulnerability in the Install Tool subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows r…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3635

Published Nov 2, 2009

The Install Tool subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote attackers to gain access by using only…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3634

Published Nov 2, 2009

Cross-site scripting (XSS) vulnerability in the Frontend Login Box (aka felogin) subcomponent in TYPO3 4.2.0 through 4.2.6 allows remote attackers to inject arbitrary web script o…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3633

Published Nov 2, 2009

Cross-site scripting (XSS) vulnerability in the t3lib_div::quoteJSvalue API function in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3bet…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3632

Published Nov 2, 2009

SQL injection vulnerability in the traditional frontend editing feature in the Frontend Editing subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3631

Published Nov 2, 2009

The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2, when the DAM extension or ftp upload is enabled, allows…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-3630

Published Nov 2, 2009

The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote authenticated users to place arbitrary web…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3629

Published Nov 2, 2009

Multiple cross-site scripting (XSS) vulnerabilities in the Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 al…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-3628

Published Nov 2, 2009

The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote authenticated users to determine an encrypt…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3821

Published Oct 28, 2009

Cross-site scripting (XSS) vulnerability in the Apache Solr Search (solr) extension 1.0.0 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3820

Published Oct 28, 2009

SQL injection vulnerability in the Flagbit Filebase (fb_filebase) extension 0.1.0 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-3819

Published Oct 28, 2009

Unspecified vulnerability in the Random Images (maag_randomimage) extension 1.6.4 and earlier for TYPO3 allows remote attackers to execute arbitrary shell commands via unspecified…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3818

Published Oct 28, 2009

Unspecified vulnerability in the session handling feature in freeCap CAPTCHA (sr_freecap) extension 1.2.0 and earlier for TYPO3 has unknown impact and attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-6699

Published Apr 10, 2009

Cross-site scripting (XSS) vulnerability in Resource Library (tjs_reslib) 0.1.0 and earlier extension for TYPO3 allows remote attackers to inject arbitrary web script or HTML via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6698

Published Apr 10, 2009

Cross-site scripting (XSS) vulnerability in TARGET-E WorldCup Bets (worldcup) 2.0.0 and earlier extension for TYPO3 allows remote attackers to inject arbitrary web script or HTML…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6697

Published Apr 10, 2009

SQL injection vulnerability in TARGET-E WorldCup Bets (worldcup) 2.0.0 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vector…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6696

Published Apr 10, 2009

SQL injection vulnerability in Fussballtippspiel (toto) 0.1.1 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6695

Published Apr 10, 2009

SQL injection vulnerability in TIMTAB social bookmark icons (timtab_sociable) 2.0.4 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via u…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 401-425 of 518 CVEsPage 17 of 21