TYPO3 T3Blog HTML Forms Cross Site Scripting and SQL Injection Vulnerabilities
BID:38030
Info
TYPO3 T3Blog HTML Forms Cross Site Scripting and SQL Injection Vulnerabilities
| Bugtraq ID: | 38030 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-0798 CVE-2010-0797 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 01 2010 12:00AM |
| Updated: | Apr 13 2015 09:02PM |
| Credit: | Marcus Krause |
| Vulnerable: |
Typo3 T3Blog 0.6.2 |
| Not Vulnerable: |
Typo3 T3Blog 0.8 |
Discussion
TYPO3 T3Blog HTML Forms Cross Site Scripting and SQL Injection Vulnerabilities
TYPO3 T3Blog is prone to multiple SQL-injection and cross-site scripting vulnerabilities.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
TYPO3 T3Blog 0.6.2 and prior are vulnerable.
TYPO3 T3Blog is prone to multiple SQL-injection and cross-site scripting vulnerabilities.
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
TYPO3 T3Blog 0.6.2 and prior are vulnerable.
Exploit / POC
TYPO3 T3Blog HTML Forms Cross Site Scripting and SQL Injection Vulnerabilities
An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
TYPO3 T3Blog HTML Forms Cross Site Scripting and SQL Injection Vulnerabilities
Solution:
The vendor has released an update. Please see the references for details.
Solution:
The vendor has released an update. Please see the references for details.
References
TYPO3 T3Blog HTML Forms Cross Site Scripting and SQL Injection Vulnerabilities
References:
References: