| Vulnerability Name: | CVE-2010-3659 (CCN-134109) |
| Assigned: | 2010-07-28 |
| Published: | 2010-07-28 |
| Updated: | 2017-11-07 |
| Summary: | Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 CMS 4.1.x before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4, and 4.4.x before 4.4.1 allow remote authenticated backend users to inject arbitrary web script or HTML via unspecified parameters to the extension manager, or unspecified parameters to unknown backend forms.
|
| CVSS v3 Severity: | 5.4 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N) 5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)| Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): Low User Interaction (UI): Required | | Scope: | Scope (S): Changed
| | Impact Metrics: | Confidentiality (C): Low Integrity (I): Low Availibility (A): None | 6.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N) 5.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)| Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): Required | | Scope: | Scope (S): Changed
| | Impact Metrics: | Confidentiality (C): Low Integrity (I): Low Availibility (A): None |
|
| CVSS v2 Severity: | 3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N)| Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Medium Authentication (Au): Single_Instance | | Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None | 5.5 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N)| Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Athentication (Au): Single_Instance
| | Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): None |
|
| Vulnerability Type: | CWE-79
|
| Vulnerability Consequences: | Cross-Site Scripting |
| References: | Source: MITRE Type: CNA CVE-2010-3659
Source: MLIST Type: Mailing List [oss-security] 20100928 CVE requests: POE::Component::IRC, Alien Arena, Babiloo, Typo3, abcm2ps, ModSecurity, Linux kernel
Source: MLIST Type: Mailing List [oss-security] 20140212 Re: Old CVE ids, public, but still
Source: BID Type: Third Party Advisory, VDB Entry 42029
Source: CCN Type: BID-42029 TYPO3 Core TYPO3-SA-2010-012 Multiple Remote Security Vulnerabilities
Source: XF Type: UNKNOWN typo3-cve20103659-xss(134109)
Source: MISC Type: Third Party Advisory https://security-tracker.debian.org/tracker/CVE-2010-3659/
Source: CCN Type: TYPO3-SA-2010-012 Multiple vulnerabilities in TYPO3 Core
Source: CONFIRM Type: Vendor Advisory https://typo3.org/teams/security/security-bulletins/typo3-core/typo3-sa-2010-012/
|
| Vulnerable Configuration: | Configuration 1: cpe:/a:typo3:typo3:4.1.0:*:*:*:*:*:*:*OR cpe:/a:typo3:typo3:4.1.1:*:*:*:*:*:*:*OR cpe:/a:typo3:typo3:4.1.2:*:*:*:*:*:*:*OR cpe:/a:typo3:typo3:4.1.3:*:*:*:*:*:*:*OR cpe:/a:typo3:typo3:4.1.4:*:*:*:*:*:*:*OR cpe:/a:typo3:typo3:4.1.5:*:*:*:*:*:*:*OR cpe:/a:typo3:typo3:4.1.6:*:*:*:*:*:*:*OR cpe:/a:typo3:typo3:4.1.7:*:*:*:*:*:*:*OR cpe:/a:typo3:typo3:4.1.8:*:*:*:*:*:*:*OR cpe:/a:typo3:typo3:4.1.9:*:*:*:*:*:*:*OR cpe:/a:typo3:typo3:4.1.10:*:*:*:*:*:*:*OR cpe:/a:typo3:typo3:4.1.11:*:*:*:*:*:*:*OR cpe:/a:typo3:typo3:4.1.12:*:*:*:*:*:*:*OR cpe:/a:typo3:typo3:4.1.13:*:*:*:*:*:*:*OR cpe:/a:typo3:typo3:4.2.0:*:*:*:*:*:*:*OR cpe:/a:typo3:typo3:4.2.1:*:*:*:*:*:*:*OR cpe:/a:typo3:typo3:4.2.2:*:*:*:*:*:*:*OR cpe:/a:typo3:typo3:4.2.3:*:*:*:*:*:*:*OR cpe:/a:typo3:typo3:4.2.4:*:*:*:*:*:*:*OR cpe:/a:typo3:typo3:4.2.5:*:*:*:*:*:*:*OR cpe:/a:typo3:typo3:4.2.6:*:*:*:*:*:*:*OR cpe:/a:typo3:typo3:4.2.7:*:*:*:*:*:*:*OR cpe:/a:typo3:typo3:4.2.8:*:*:*:*:*:*:*OR cpe:/a:typo3:typo3:4.2.9:*:*:*:*:*:*:*OR cpe:/a:typo3:typo3:4.2.10:*:*:*:*:*:*:*OR cpe:/a:typo3:typo3:4.2.11:*:*:*:*:*:*:*OR cpe:/a:typo3:typo3:4.2.12:*:*:*:*:*:*:*OR cpe:/a:typo3:typo3:4.3.0:*:*:*:*:*:*:*OR cpe:/a:typo3:typo3:4.3.1:*:*:*:*:*:*:*OR cpe:/a:typo3:typo3:4.3.2:*:*:*:*:*:*:*OR cpe:/a:typo3:typo3:4.3.3:*:*:*:*:*:*:*OR cpe:/a:typo3:typo3:4.4.0:*:*:*:*:*:*:*
Denotes that component is vulnerable |
| Oval Definitions |
|
| BACK |