Skip to main content

Vendor archive

typo3 CVEs

Beta · best-effort

518 CVEs tagged to vendor typo317 Critical, 202 High, 269 Medium, 30 Low, 0 Unrated.

CVE-2008-4657

Published Oct 22, 2008

SQL injection vulnerability in the Econda Plugin (econda) 0.0.2 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-4656

Published Oct 22, 2008

SQL injection vulnerability in the Frontend Users View (feusersview) 0.1.6 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecifie…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-4655

Published Oct 22, 2008

SQL injection vulnerability in the Simple survey (simplesurvey) 1.7.0 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vec…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-4188

Published Sep 23, 2008

Unspecified vulnerability in the TYPO3 Secure Directory (kw_secdir) extension before 1.0.2 allows remote attackers to execute arbitrary code via unknown vectors related to "inject…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-3028

Published Jul 7, 2008

Multiple cross-site scripting (XSS) vulnerabilities in the Send-A-Card (sr_sendcard) extension 2.2.2 and earlier for TYPO3 allow remote attackers to inject arbitrary web script or…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3029

Published Jul 7, 2008

Cross-site scripting (XSS) vulnerability in the WEC Discussion Forum (wec_discussion) extension 1.6.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3032

Published Jul 7, 2008

Cross-site scripting (XSS) vulnerability in the phpMyAdmin (phpmyadmin) extension 3.0.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via un…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3037

Published Jul 7, 2008

Cross-site scripting (XSS) vulnerability in the Address Directory (sp_directory) extension 0.2.10 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or H…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3038

Published Jul 7, 2008

SQL injection vulnerability in the Address Directory (sp_directory) extension 0.2.10 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecifie…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3039

Published Jul 7, 2008

SQL injection vulnerability in the DAM Frontend (dam_frontend) extension 0.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vect…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3040

Published Jul 7, 2008

Unspecified vulnerability in the DAM Frontend (dam_frontend) extension 0.1.0 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3041

Published Jul 7, 2008

Unspecified vulnerability in the DAM Frontend (dam_frontend) extension 0.1.0 and earlier for TYPO3 has unknown impact and attack vectors related to "broken access control."

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3042

Published Jul 7, 2008

Unspecified vulnerability in the DAM Frontend (dam_frontend) extension 0.1.0 and earlier for TYPO3 has unknown impact and attack vectors related to "Improper Error Handling."

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-3043

Published Jul 7, 2008

Unspecified vulnerability in the WEC Discussion Forum (wec_discussion) extension 1.6.2 and earlier for TYPO3 allows attackers to execute arbitrary code via vectors related to "cer…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3044

Published Jul 7, 2008

SQL injection vulnerability in the News Calendar (newscalendar) extension 1.0.7 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vec…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3045

Published Jul 7, 2008

Unspecified vulnerability in the Industry Database (aka Branchendatenbank pro_industrydb) extension 1.0.0 and earlier for TYPO3 has unknown impact and attack vectors related to "I…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3046

Published Jul 7, 2008

Incomplete blacklist vulnerability in the Packman (kb_packman) extension 0.2.1 and earlier for TYPO3 has unknown impact and attack vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3047

Published Jul 7, 2008

Incomplete blacklist vulnerability in the KB Unpack (kb_unpack) extension 0.1.0 and earlier for TYPO3 has unknown impact and attack vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3048

Published Jul 7, 2008

Unspecified vulnerability in the PDF Generator 2 (pdf_generator2) extension 0.5.0 and earlier for TYPO3 has unknown impact and attack vectors related to "Unprotected test function…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3049

Published Jul 7, 2008

The PDF Generator 2 (pdf_generator2) extension 0.5.0 and earlier for TYPO3 allows attackers to obtain sensitive information via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3050

Published Jul 7, 2008

Unspecified vulnerability in the PDF Generator 2 (pdf_generator2) extension 0.5.0 and earlier for TYPO3 allows attackers to cause a denial of service via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3051

Published Jul 7, 2008

SQL injection vulnerability in the Pinboard extension 0.0.6 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3052

Published Jul 7, 2008

Unspecified vulnerability in the SQL Frontend (mh_omsqlio) extension 1.0.11 and earlier for TYPO3 allows remote attackers to cause a denial of service via unknown vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3053

Published Jul 7, 2008

SQL injection vulnerability in the SQL Frontend (mh_omsqlio) extension 1.0.11 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vecto…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3054

Published Jul 7, 2008

SQL injection vulnerability in the Branchenbuch (aka Yellow Pages o (mh_branchenbuch) extension 0.8.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL comman…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 476-500 of 518 CVEsPage 20 of 21