Vulnerability Name:

CVE-2012-5889 (CCN-74461)

Assigned:2012-03-28
Published:2012-03-28
Updated:2017-08-29
Summary:Cross-site scripting (XSS) vulnerability in the powermail extension before 1.6.5 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-79
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2012-5889

Source: CCN
Type: TYPO3 Web Site
TYPO3 - the Enterprise Open Source CMS: Home

Source: CCN
Type: TYPO3-EXT-SA-2012-004
Cross-Site Scripting vulnerability in extension powermail for TYPO3 (powermail)

Source: MISC
Type: Patch, Vendor Advisory
http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2012-004/

Source: CCN
Type: BID-52775
TYPO3 powermail Unspecified Cross Site Scripting Vulnerability

Source: XF
Type: UNKNOWN
typo3-powermail-unspecified-xss(74461)

Source: XF
Type: UNKNOWN
typo3-powermail-unspecified-xss(74461)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:alex_kellner:powermail:1.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.0.5:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.0.6:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.0.7:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.0.8:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.0.9:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.0.10:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.0.11:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.0.12:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.1.3:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.1.5:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.1.6:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.1.7:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.1.8:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.1.9:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.1.10:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.2.3:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.2.4:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.3.2:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.3.3:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.3.4:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.3.5:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.3.6:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.3.7:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.3.8:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.3.9:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.3.10:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.3.11:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.3.12:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.3.13:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.3.14:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.3.15:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.3.16:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.4.1:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.4.2:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.4.3:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.4.4:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.4.5:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.4.6:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.4.7:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.4.8:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.4.9:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.4.10:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.4.11:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.4.12:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.4.13:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.4.14:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.4.15:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.4.16:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.4.17:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.4.18:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.5.0:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:1.5.3:*:*:*:*:*:*:*
  • OR cpe:/a:alex_kellner:powermail:*:*:*:*:*:*:*:* (Version <= 1.6.4)
  • OR cpe:/a:typo3:typo3:-:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    alex_kellner powermail 1.0.1
    alex_kellner powermail 1.0.2
    alex_kellner powermail 1.0.3
    alex_kellner powermail 1.0.4
    alex_kellner powermail 1.0.5
    alex_kellner powermail 1.0.6
    alex_kellner powermail 1.0.7
    alex_kellner powermail 1.0.8
    alex_kellner powermail 1.0.9
    alex_kellner powermail 1.0.10
    alex_kellner powermail 1.0.11
    alex_kellner powermail 1.0.12
    alex_kellner powermail 1.1.0
    alex_kellner powermail 1.1.1
    alex_kellner powermail 1.1.2
    alex_kellner powermail 1.1.3
    alex_kellner powermail 1.1.4
    alex_kellner powermail 1.1.5
    alex_kellner powermail 1.1.6
    alex_kellner powermail 1.1.7
    alex_kellner powermail 1.1.8
    alex_kellner powermail 1.1.9
    alex_kellner powermail 1.1.10
    alex_kellner powermail 1.2.0
    alex_kellner powermail 1.2.1
    alex_kellner powermail 1.2.2
    alex_kellner powermail 1.2.3
    alex_kellner powermail 1.2.4
    alex_kellner powermail 1.3.1
    alex_kellner powermail 1.3.2
    alex_kellner powermail 1.3.3
    alex_kellner powermail 1.3.4
    alex_kellner powermail 1.3.5
    alex_kellner powermail 1.3.6
    alex_kellner powermail 1.3.7
    alex_kellner powermail 1.3.8
    alex_kellner powermail 1.3.9
    alex_kellner powermail 1.3.10
    alex_kellner powermail 1.3.11
    alex_kellner powermail 1.3.12
    alex_kellner powermail 1.3.13
    alex_kellner powermail 1.3.14
    alex_kellner powermail 1.3.15
    alex_kellner powermail 1.3.16
    alex_kellner powermail 1.4.1
    alex_kellner powermail 1.4.2
    alex_kellner powermail 1.4.3
    alex_kellner powermail 1.4.4
    alex_kellner powermail 1.4.5
    alex_kellner powermail 1.4.6
    alex_kellner powermail 1.4.7
    alex_kellner powermail 1.4.8
    alex_kellner powermail 1.4.9
    alex_kellner powermail 1.4.10
    alex_kellner powermail 1.4.11
    alex_kellner powermail 1.4.12
    alex_kellner powermail 1.4.13
    alex_kellner powermail 1.4.14
    alex_kellner powermail 1.4.15
    alex_kellner powermail 1.4.16
    alex_kellner powermail 1.4.17
    alex_kellner powermail 1.4.18
    alex_kellner powermail 1.5.0
    alex_kellner powermail 1.5.1
    alex_kellner powermail 1.5.3
    alex_kellner powermail *
    typo3 typo3 -