TYPO3 Core TYPO3-CORE-SA-2012-004 Multiple Remote Security Vulnerabilities
BID:55052
Info
TYPO3 Core TYPO3-CORE-SA-2012-004 Multiple Remote Security Vulnerabilities
| Bugtraq ID: | 55052 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 16 2012 12:00AM |
| Updated: | Aug 16 2012 12:00AM |
| Credit: | Felix Wilhelm, Pavel Vaysband, Markus Bucher, Susanne Moog, Jan Bednarik, Mario Rimann, Georg Ringer, Andreas Schnapp, and Christian Nösterer |
| Vulnerable: |
Typo3 Typo3 4.6.6 Typo3 Typo3 4.6.1 Typo3 Typo3 4.6 Typo3 Typo3 4.5.13 Typo3 Typo3 4.5.8 Typo3 Typo3 4.5.7 Typo3 Typo3 4.5.5 Typo3 Typo3 4.7 Typo3 Typo3 4.6.8 Typo3 Typo3 4.6.2 Typo3 Typo3 4.5.9 Typo3 Typo3 4.5.6 Typo3 Typo3 4.5.6 Typo3 Typo3 4.5.4 Typo3 Typo3 4.5.3 Typo3 Typo3 4.5.2 Typo3 Typo3 4.5.15 Typo3 Typo3 4.5.1 Typo3 Typo3 4.5 |
| Not Vulnerable: | |
Discussion
TYPO3 Core TYPO3-CORE-SA-2012-004 Multiple Remote Security Vulnerabilities
TYPO3 is prone to a cross-site scripting vulnerability, an HTML-injection vulnerability, a PHP-code execution vulnerability, and an information-disclosure vulnerability.
An attacker may leverage these issues to execute arbitrary PHP code in the context of the web server process and arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, and obtain sensitive information.
TYPO3 is prone to a cross-site scripting vulnerability, an HTML-injection vulnerability, a PHP-code execution vulnerability, and an information-disclosure vulnerability.
An attacker may leverage these issues to execute arbitrary PHP code in the context of the web server process and arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, and obtain sensitive information.
Exploit / POC
TYPO3 Core TYPO3-CORE-SA-2012-004 Multiple Remote Security Vulnerabilities
Attackers can use a browser to exploit these issues. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting victim to follow a malicious URI.
Attackers can use a browser to exploit these issues. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
TYPO3 Core TYPO3-CORE-SA-2012-004 Multiple Remote Security Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
TYPO3 Core TYPO3-CORE-SA-2012-004 Multiple Remote Security Vulnerabilities
References:
References:
- TYPO3 Homepage (TYPO3)