TYPO3 'indexed_search' Extension SQL Injection Vulnerability
BID:26871
Info
TYPO3 'indexed_search' Extension SQL Injection Vulnerability
| Bugtraq ID: | 26871 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6381 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 10 2007 12:00AM |
| Updated: | Jan 03 2008 02:10PM |
| Credit: | Henning Pingel is credited with the discovery of this vulnerability. |
| Vulnerable: |
Typo3 Typo3 4.0.5 Typo3 Typo3 4.0.4 Typo3 Typo3 4.0.3 Typo3 Typo3 4.0.2 Typo3 Typo3 4.0.1 Typo3 Typo3 3.7 .0 Typo3 Typo3 3.6.2 Typo3 Typo3 3.5 b5 Typo3 Typo3 3.5 .0 Typo3 Typo3 4.1beta Typo3 Typo3 4.1 RC1 Typo3 Typo3 4.0 Typo3 Typo3 3.8 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
Typo3 Typo3 4.1.4 Typo3 Typo3 4.0.8 |
Discussion
TYPO3 'indexed_search' Extension SQL Injection Vulnerability
TYPO3 is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
This issue affects versions prior to:
TYPO3 4.0.8 from the 3.x and 4.x branches
TYPO3 4.1.4 from the 4.1.x branch
TYPO3 is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
This issue affects versions prior to:
TYPO3 4.0.8 from the 3.x and 4.x branches
TYPO3 4.1.4 from the 4.1.x branch
Exploit / POC
TYPO3 'indexed_search' Extension SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
TYPO3 'indexed_search' Extension SQL Injection Vulnerability
Solution:
The vendor has released updates to address this issue. Please see the references for more information.
Typo3 Typo3 3.8
Typo3 Typo3 4.1 RC1
Typo3 Typo3 4.1beta
Typo3 Typo3 4.0
Typo3 Typo3 3.5 b5
Typo3 Typo3 3.5 .0
Typo3 Typo3 3.6.2
Typo3 Typo3 3.7 .0
Typo3 Typo3 4.0.1
Typo3 Typo3 4.0.2
Typo3 Typo3 4.0.3
Typo3 Typo3 4.0.4
Typo3 Typo3 4.0.5
Solution:
The vendor has released updates to address this issue. Please see the references for more information.
Typo3 Typo3 3.8
-
Typo3 dummy-4.0.8.tar.gz
http://typo3.org/fileadmin/dl/packages/dummy-4.0.8.tar.gz
Typo3 Typo3 4.1 RC1
-
Typo3 dummy-4.1.4.tar.gz
http://typo3.org/fileadmin/dl/packages/dummy-4.1.4.tar.gz
Typo3 Typo3 4.1beta
-
Typo3 dummy-4.1.4.tar.gz
http://typo3.org/fileadmin/dl/packages/dummy-4.1.4.tar.gz
Typo3 Typo3 4.0
-
Typo3 dummy-4.0.8.tar.gz
http://typo3.org/fileadmin/dl/packages/dummy-4.0.8.tar.gz
Typo3 Typo3 3.5 b5
-
Typo3 dummy-4.0.8.tar.gz
http://typo3.org/fileadmin/dl/packages/dummy-4.0.8.tar.gz
Typo3 Typo3 3.5 .0
-
Typo3 dummy-4.0.8.tar.gz
http://typo3.org/fileadmin/dl/packages/dummy-4.0.8.tar.gz
Typo3 Typo3 3.6.2
-
Typo3 dummy-4.0.8.tar.gz
http://typo3.org/fileadmin/dl/packages/dummy-4.0.8.tar.gz
Typo3 Typo3 3.7 .0
-
Typo3 dummy-4.0.8.tar.gz
http://typo3.org/fileadmin/dl/packages/dummy-4.0.8.tar.gz
Typo3 Typo3 4.0.1
-
Typo3 dummy-4.0.8.tar.gz
http://typo3.org/fileadmin/dl/packages/dummy-4.0.8.tar.gz
Typo3 Typo3 4.0.2
-
Typo3 dummy-4.0.8.tar.gz
http://typo3.org/fileadmin/dl/packages/dummy-4.0.8.tar.gz
Typo3 Typo3 4.0.3
-
Typo3 dummy-4.0.8.tar.gz
http://typo3.org/fileadmin/dl/packages/dummy-4.0.8.tar.gz
Typo3 Typo3 4.0.4
-
Typo3 dummy-4.0.8.tar.gz
http://typo3.org/fileadmin/dl/packages/dummy-4.0.8.tar.gz
Typo3 Typo3 4.0.5
-
Typo3 dummy-4.0.8.tar.gz
http://typo3.org/fileadmin/dl/packages/dummy-4.0.8.tar.gz
References
TYPO3 'indexed_search' Extension SQL Injection Vulnerability
References:
References: