TYPO3 TGM gallery Unspecified SQL Injection Vulnerability
BID:49840
Info
TYPO3 TGM gallery Unspecified SQL Injection Vulnerability
| Bugtraq ID: | 49840 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 28 2011 12:00AM |
| Updated: | Sep 28 2011 12:00AM |
| Credit: | Steffen Thierock |
| Vulnerable: |
Typo3 TGM gallery 0.0.2 |
| Not Vulnerable: |
Typo3 TGM gallery 0.0.3 |
Discussion
TYPO3 TGM gallery Unspecified SQL Injection Vulnerability
The TGM gallery extension for TYPO3 is prone to an unspecified SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to TGM gallery 0.0.3 are vulnerable.
The TGM gallery extension for TYPO3 is prone to an unspecified SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Versions prior to TGM gallery 0.0.3 are vulnerable.
References
TYPO3 TGM gallery Unspecified SQL Injection Vulnerability
References:
References: