TYPO3 Parish of the Holy Spirit Religious Art Gallery Multiple Vulnerabilities
BID:37628
Info
TYPO3 Parish of the Holy Spirit Religious Art Gallery Multiple Vulnerabilities
| Bugtraq ID: | 37628 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-4398 CVE-2009-4399 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2009 12:00AM |
| Updated: | Jan 06 2010 03:12PM |
| Credit: | Georg Ringer |
| Vulnerable: |
Typo3 Parish of the Holy Spirit Religious Art Gallery 0.1.2 |
| Not Vulnerable: | |
Discussion
TYPO3 Parish of the Holy Spirit Religious Art Gallery Multiple Vulnerabilities
The Parish of the Holy Spirit Religious Art Gallery extension for TYPO3 is prone to a cross-site scripting vulnerability and an SQL-injection vulnerability because it fails to properly sanitize user-supplied input.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Parish of the Holy Spirit Religious Art Gallery 0.1.2 and prior versions are vulnerable.
NOTE: Reports indicate that this extension is no longer maintained.
The Parish of the Holy Spirit Religious Art Gallery extension for TYPO3 is prone to a cross-site scripting vulnerability and an SQL-injection vulnerability because it fails to properly sanitize user-supplied input.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Parish of the Holy Spirit Religious Art Gallery 0.1.2 and prior versions are vulnerable.
NOTE: Reports indicate that this extension is no longer maintained.
Exploit / POC
TYPO3 Parish of the Holy Spirit Religious Art Gallery Multiple Vulnerabilities
An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
TYPO3 Parish of the Holy Spirit Religious Art Gallery Multiple Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
TYPO3 Parish of the Holy Spirit Religious Art Gallery Multiple Vulnerabilities
References:
References: