TYPO3 Core TYPO3-CORE-SA-2011-001 Multiple Remote Security Vulnerabilities
BID:49072
Info
TYPO3 Core TYPO3-CORE-SA-2011-001 Multiple Remote Security Vulnerabilities
| Bugtraq ID: | 49072 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 08 2011 12:00AM |
| Updated: | Aug 08 2011 12:00AM |
| Credit: | Marco Bresch, Sebastian Schinzel, Georg Ringer of TYPO3 Security Team, Steffen Gebert of TYPO3 Core Team, Mads Chr. Olesen, Marcus Krause of TYPO3 Security Team, Vladimir Podkovanov and Helmut Hummel of TYPO3 Security Team. |
| Vulnerable: |
Typo3 Typo3 4.4.1 Typo3 Typo3 4.4 Typo3 Typo3 4.3.3 Typo3 Typo3 4.3.2 Typo3 Typo3 4.3.1 Typo3 Typo3 4.3 Typo3 Typo3 4.5.3 Typo3 Typo3 4.5 Typo3 Typo3 4.4.8 Typo3 Typo3 4.4.5 Typo3 Typo3 4.4.4 Typo3 Typo3 4.4.3 Typo3 Typo3 4.3.9 Typo3 Typo3 4.3.7 Typo3 Typo3 4.3.6 Typo3 Typo3 4.3.4 Typo3 Typo3 4.3.11 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: |
Typo3 Typo3 4.5.4 Typo3 Typo3 4.4.9 Typo3 Typo3 4.3.12 |
Discussion
TYPO3 Core TYPO3-CORE-SA-2011-001 Multiple Remote Security Vulnerabilities
TYPO3 is prone to multiple remote vulnerabilities, including information-disclosure, security-bypass and cross-site scripting vulnerabilities.
An attacker can exploit these issues to bypass security restrictions, to view sensitive information, and to steal cookie-based authentication credentials. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
TYPO3 is prone to multiple remote vulnerabilities, including information-disclosure, security-bypass and cross-site scripting vulnerabilities.
An attacker can exploit these issues to bypass security restrictions, to view sensitive information, and to steal cookie-based authentication credentials. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
Exploit / POC
TYPO3 Core TYPO3-CORE-SA-2011-001 Multiple Remote Security Vulnerabilities
Attackers can use a browser to exploit most of these issues. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting victim to follow a malicious URI.
Attackers can use a browser to exploit most of these issues. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
TYPO3 Core TYPO3-CORE-SA-2011-001 Multiple Remote Security Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
TYPO3 Core TYPO3-CORE-SA-2011-001 Multiple Remote Security Vulnerabilities
References:
References: