Skip to main content

Vendor archive

typo3 CVEs

Beta · best-effort

518 CVEs tagged to vendor typo317 Critical, 202 High, 269 Medium, 30 Low, 0 Unrated.

CVE-2008-6690

Published Apr 10, 2009

Unspecified vulnerability in nepa-design.de Spam Protection (nd_antispam) extension 1.0.3 for TYPO3 allows remote attackers to modify configuration via unknown vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6689

Published Apr 10, 2009

SQL injection vulnerability in JobControl (dmmjobcontrol) 1.15.0 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6688

Published Apr 10, 2009

Cross-site scripting (XSS) vulnerability in JobControl (dmmjobcontrol) 1.15.0 and earlier extension for TYPO3 allows remote attackers to inject arbitrary web script or HTML via un…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6687

Published Apr 10, 2009

Cross-site scripting (XSS) vulnerability in DCD GoogleMap (dcdgooglemap) 1.1.0 and earlier extension for TYPO3 allows remote attackers to inject arbitrary web script or HTML via u…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6686

Published Apr 10, 2009

SQL injection vulnerability in CoolURI (cooluri) 1.0.11 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6685

Published Apr 10, 2009

Unspecified vulnerability in Frontend Filemanager (air_filemanager) 0.6.1 and earlier extension for TYPO3 allows remote attackers to execute arbitrary commands via unknown vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6630

Published Apr 7, 2009

Directory traversal vulnerability in the wt_gallery extension 2.5.0 and earlier for TYPO3 allows remote attackers to read arbitrary image files and determine directory structure v…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6595

Published Apr 3, 2009

SQL injection vulnerability in the pmk_rssnewsexport extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6462

Published Mar 13, 2009

SQL injection vulnerability in the My quiz and poll (myquizpoll) extension before 0.1.4 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6461

Published Mar 13, 2009

SQL injection vulnerability in the Random Prayer 2 (ste_prayer2) extension before 0.0.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6460

Published Mar 13, 2009

SQL injection vulnerability in the Simple Random Objects (mw_random_objects) extension 1.0.3 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via un…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6459

Published Mar 13, 2009

SQL injection vulnerability in the auto BE User Registration (autobeuser) extension 0.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspe…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6458

Published Mar 13, 2009

SQL injection vulnerability in the FE address edit for tt_address & direct mail (dmaddredit) extension 0.4.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6457

Published Mar 13, 2009

SQL injection vulnerability in the Swigmore institute (cgswigmore) extension before 0.1.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vecto…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6456

Published Mar 13, 2009

SQL injection vulnerability in the HBook (h_book) extension 2.3.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0816

Published Mar 5, 2009

Multiple cross-site scripting (XSS) vulnerabilities in the backend user interface in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 before 4.2.6, and 4.3alph…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0815

Published Mar 5, 2009

The jumpUrl mechanism in class.tslib_fe.php in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 before 4.2.6, and 4.3alpha1 leaks a hash secret (juHash) in an…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6346

Published Feb 27, 2009

Cross-site scripting (XSS) vulnerability in the DR Wiki (dr_wiki) extension 1.7.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecif…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6344

Published Feb 27, 2009

SQL injection vulnerability in the TU-Clausthal Staff (tuc_staff) 0.3.0 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified v…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6343

Published Feb 27, 2009

Cross-site scripting (XSS) vulnerability in the TU-Clausthal ODIN (tuc_odin) extension 0.0.1, 0.1.0, 0.1.1, and 0.2.0 for TYPO3 allows remote attackers to inject arbitrary web scr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6341

Published Feb 27, 2009

Cross-site scripting (XSS) vulnerability in the SB Universal Plugin (SBuniplug) extension 2.0.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTM…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 426-450 of 518 CVEsPage 18 of 21