RSS Feed From Records Extension Unspecified SQL Injection Vulnerability
BID:60842
Info
RSS Feed From Records Extension Unspecified SQL Injection Vulnerability
| Bugtraq ID: | 60842 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-4721 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 19 2013 12:00AM |
| Updated: | Feb 19 2013 12:00AM |
| Credit: | Andy Grunwald |
| Vulnerable: |
Typo3 RSS Feed From Records 1.0 |
| Not Vulnerable: | |
Discussion
RSS Feed From Records Extension Unspecified SQL Injection Vulnerability
The RSS feed from records extension for TYPO3 is prone to an unspecified SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
RSS feed from records 1.0.0 and prior are vulnerable.
The RSS feed from records extension for TYPO3 is prone to an unspecified SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
RSS feed from records 1.0.0 and prior are vulnerable.
Exploit / POC
RSS Feed From Records Extension Unspecified SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
References
RSS Feed From Records Extension Unspecified SQL Injection Vulnerability
References:
References: