TYPO3 Core TYPO3-CORE-SA-2012-001 Multiple Remote Security Vulnerabilities
BID:52771
Info
TYPO3 Core TYPO3-CORE-SA-2012-001 Multiple Remote Security Vulnerabilities
| Bugtraq ID: | 52771 |
| Class: | Unknown |
| CVE: |
CVE-2012-1606 CVE-2012-1607 CVE-2012-1608 CVE-2012-1605 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 28 2012 12:00AM |
| Updated: | Sep 04 2012 10:40PM |
| Credit: | Helmut Hummel, Georg Ringer, Chris John Riley, Marc Wöhlken and Oliver Klee |
| Vulnerable: |
Typo3 Typo3 4.6.6 Typo3 Typo3 4.6.1 Typo3 Typo3 4.6 Typo3 Typo3 4.5.13 Typo3 Typo3 4.5.8 Typo3 Typo3 4.5.7 Typo3 Typo3 4.5.5 Typo3 Typo3 4.4.13 Typo3 Typo3 4.4.11 Typo3 Typo3 4.4.1 Typo3 Typo3 4.4 Typo3 Typo3 4.7 Typo3 Typo3 4.6.2 Typo3 Typo3 4.5.9 Typo3 Typo3 4.5.6 Typo3 Typo3 4.5.6 Typo3 Typo3 4.5.4 Typo3 Typo3 4.5.3 Typo3 Typo3 4.5.2 Typo3 Typo3 4.5.1 Typo3 Typo3 4.5 Typo3 Typo3 4.4.9 Typo3 Typo3 4.4.8 Typo3 Typo3 4.4.5 Typo3 Typo3 4.4.4 Typo3 Typo3 4.4.4 Typo3 Typo3 4.4.3 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
TYPO3 Core TYPO3-CORE-SA-2012-001 Multiple Remote Security Vulnerabilities
TYPO3 is prone to multiple remote vulnerabilities, including information-disclosure, insecure unserializing, and cross-site scripting vulnerabilities.
An attacker can exploit these issues to view sensitive information, unserialize arbitrary objects, and steal cookie-based authentication credentials. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
TYPO3 is prone to multiple remote vulnerabilities, including information-disclosure, insecure unserializing, and cross-site scripting vulnerabilities.
An attacker can exploit these issues to view sensitive information, unserialize arbitrary objects, and steal cookie-based authentication credentials. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
Exploit / POC
TYPO3 Core TYPO3-CORE-SA-2012-001 Multiple Remote Security Vulnerabilities
Attackers can use a browser to exploit most of these issues.
Attackers can use a browser to exploit most of these issues.
Solution / Fix
TYPO3 Core TYPO3-CORE-SA-2012-001 Multiple Remote Security Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
TYPO3 Core TYPO3-CORE-SA-2012-001 Multiple Remote Security Vulnerabilities
References:
References: