Revision Date: | 2014-06-23 | Version: | 18 |
Title: | DSA-1926 typo3-src -- several vulnerabilities |
Description: | Several remote vulnerabilities have been discovered in the TYPO3 web content management framework. The Common Vulnerabilities and Exposures project identifies the following problems: The Backend subcomponent allows remote authenticated users to determine an encryption key via crafted input to a form field. Multiple cross-site scripting (XSS) vulnerabilities in the Backend subcomponent allow remote authenticated users to inject arbitrary web script or HTML. The Backend subcomponent allows remote authenticated users to place arbitrary web sites in TYPO3 backend framesets via crafted parameters. The Backend subcomponent, when the DAM extension or ftp upload is enabled, allows remote authenticated users to execute arbitrary commands via shell metacharacters in a filename. SQL injection vulnerability in the traditional frontend editing feature in the Frontend Editing subcomponent allows remote authenticated users to execute arbitrary SQL commands. Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script. Cross-site scripting (XSS) vulnerability in the Frontend Login Box (aka felogin) subcomponent allows remote attackers to inject arbitrary web script or HTML. The Install Tool subcomponent allows remote attackers to gain access by using only the password's md5 hash as a credential. Cross-site scripting (XSS) vulnerability in the Install Tool subcomponent allows remote attackers to inject arbitrary web script or HTML. |
Family: | unix | Class: | patch |
Status: | ACCEPTED | Reference(s): | CVE-2009-3628 CVE-2009-3629 CVE-2009-3630 CVE-2009-3631 CVE-2009-3632 CVE-2009-3633 CVE-2009-3634 CVE-2009-3635 CVE-2009-3636 DSA-1926
|
Platform(s): | Debian GNU/Linux 4.0 Debian GNU/Linux 5.0
| Product(s): | typo3-src
|
Definition Synopsis |
Release section Debian GNU/Linux 5.0 is installed
AND Installed architecture is all
AND Packages section
typo3 is earlier than 4.2.5-1+lenny2
OR typo3-src-4.2 is earlier than 4.2.5-1+lenny2
OR Release section
Debian GNU/Linux 4.0 is installed.
AND Installed architecture is all
AND Packages section
typo3 is earlier than 4.0.2+debian-9
OR typo3-src-4.0 is earlier than 4.0.2+debian-9
|