TYPO3 Exception Handler Cross Site Scripting Vulnerability
BID:53047
Info
TYPO3 Exception Handler Cross Site Scripting Vulnerability
| Bugtraq ID: | 53047 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-2112 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 17 2012 12:00AM |
| Updated: | Apr 20 2012 07:40PM |
| Credit: | Helmut Hummel |
| Vulnerable: |
Typo3 Typo3 4.6.6 Typo3 Typo3 4.6.1 Typo3 Typo3 4.6 Typo3 Typo3 4.5.13 Typo3 Typo3 4.5.8 Typo3 Typo3 4.5.7 Typo3 Typo3 4.5.5 Typo3 Typo3 4.4.13 Typo3 Typo3 4.4.11 Typo3 Typo3 4.4.1 Typo3 Typo3 4.4 Typo3 Typo3 4.7 Typo3 Typo3 4.6.2 Typo3 Typo3 4.5.9 Typo3 Typo3 4.5.6 Typo3 Typo3 4.5.6 Typo3 Typo3 4.5.4 Typo3 Typo3 4.5.3 Typo3 Typo3 4.5.2 Typo3 Typo3 4.5.1 Typo3 Typo3 4.5 Typo3 Typo3 4.4.9 Typo3 Typo3 4.4.8 Typo3 Typo3 4.4.5 Typo3 Typo3 4.4.4 Typo3 Typo3 4.4.4 Typo3 Typo3 4.4.3 Typo3 Typo3 4.4.11 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: |
Typo3 Typo3 4.6.8 Typo3 Typo3 4.5.15 Typo3 Typo3 4.4.15 |
Discussion
TYPO3 Exception Handler Cross Site Scripting Vulnerability
TYPO3 is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary HTML and script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
This issue affects the following versions:
TYPO3 4.4.0 through 4.4.14
TYPO3 4.5.0 through 4.5.14
TYPO3 4.6.0 through 4.6.7
TYPO3 4.7 branch releases
TYPO3 is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary HTML and script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
This issue affects the following versions:
TYPO3 4.4.0 through 4.4.14
TYPO3 4.5.0 through 4.5.14
TYPO3 4.6.0 through 4.6.7
TYPO3 4.7 branch releases
Exploit / POC
TYPO3 Exception Handler Cross Site Scripting Vulnerability
Attackers can exploit this issue by enticing an unsuspecting victim into following a malicious URI.
Attackers can exploit this issue by enticing an unsuspecting victim into following a malicious URI.
Solution / Fix
TYPO3 Exception Handler Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
TYPO3 Exception Handler Cross Site Scripting Vulnerability
References:
References: