TYPO3 Core TYPO3-SA-2012-005 Multiple Remote Security Vulnerabilities
BID:56472
Info
TYPO3 Core TYPO3-SA-2012-005 Multiple Remote Security Vulnerabilities
| Bugtraq ID: | 56472 |
| Class: | Unknown |
| CVE: |
CVE-2012-6144 CVE-2012-6145 CVE-2012-6146 CVE-2012-6147 CVE-2012-6148 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 08 2012 12:00AM |
| Updated: | Jun 19 2013 08:07AM |
| Credit: | Thomas Worm, Oliver Hader, Johannes Feustel, and Richard Brain. |
| Vulnerable: |
Typo3 Typo3 4.6.6 Typo3 Typo3 4.6.1 Typo3 Typo3 4.6 Typo3 Typo3 4.5.13 Typo3 Typo3 4.5.8 Typo3 Typo3 4.5.7 Typo3 Typo3 4.5.5 Typo3 Typo3 4.7 Typo3 Typo3 4.6.8 Typo3 Typo3 4.6.2 Typo3 Typo3 4.5.9 Typo3 Typo3 4.5.6 Typo3 Typo3 4.5.6 Typo3 Typo3 4.5.4 Typo3 Typo3 4.5.3 Typo3 Typo3 4.5.2 Typo3 Typo3 4.5.15 Typo3 Typo3 4.5.1 Typo3 Typo3 4.5 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
TYPO3 Core TYPO3-SA-2012-005 Multiple Remote Security Vulnerabilities
TYPO3 is prone to multiple remote vulnerabilities including:
1. A cross-site scripting vulnerability
2. An information-disclosure vulnerability
3. An SQL-injection vulnerability,
4. Multiple HTML-injection vulnerabilities
Successful exploiting these issues may allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the website, steal cookie-based credentials, disclose sensitive information, access or modify data, or exploit vulnerabilities in the underlying database. Other attacks are also possible.
The follow versions are affected:
TYPO3 4.5.20 and prior
TYPO3 4.6.13 and prior
TYPO3 4.7.5 and prior
TYPO3 is prone to multiple remote vulnerabilities including:
1. A cross-site scripting vulnerability
2. An information-disclosure vulnerability
3. An SQL-injection vulnerability,
4. Multiple HTML-injection vulnerabilities
Successful exploiting these issues may allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the website, steal cookie-based credentials, disclose sensitive information, access or modify data, or exploit vulnerabilities in the underlying database. Other attacks are also possible.
The follow versions are affected:
TYPO3 4.5.20 and prior
TYPO3 4.6.13 and prior
TYPO3 4.7.5 and prior
Exploit / POC
Solution / Fix
TYPO3 Core TYPO3-SA-2012-005 Multiple Remote Security Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
TYPO3 Core TYPO3-SA-2012-005 Multiple Remote Security Vulnerabilities
References:
References:
- TYPO3 Homepage (TYPO3)