RETIRED: TYPO3 Store Locator Extension Multiple Unspecified Security Vulnerabilities
BID:61606
Info
RETIRED: TYPO3 Store Locator Extension Multiple Unspecified Security Vulnerabilities
| Bugtraq ID: | 61606 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 05 2013 12:00AM |
| Updated: | Aug 21 2013 03:27PM |
| Credit: | Ingo Schmitt |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
RETIRED: TYPO3 Store Locator Extension Multiple Unspecified Security Vulnerabilities
The Store Locator extension for TYPO3 is prone to a cross-site scripting vulnerability, a security vulnerability and an SQL-injection vulnerability.
Attackers can exploit these issues to execute arbitrary code in the context of the browser, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database; other attacks are also possible.
Store Locator 3.1.4 and prior are vulnerable.
This BID is being retired. The following individual records exist to better document the issues:
61899 TYPO3 Store Locator Extension CVE-2013-5304 Unspecified SQL Injection Vulnerability
61895 TYPO3 Store Locator Extension CVE-2013-5305 Unspecified Cross Site Scripting Vulnerability
61897 TYPO3 Store Locator Extension CVE-2013-5303 Unspecified Security Vulnerability
The Store Locator extension for TYPO3 is prone to a cross-site scripting vulnerability, a security vulnerability and an SQL-injection vulnerability.
Attackers can exploit these issues to execute arbitrary code in the context of the browser, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database; other attacks are also possible.
Store Locator 3.1.4 and prior are vulnerable.
This BID is being retired. The following individual records exist to better document the issues:
61899 TYPO3 Store Locator Extension CVE-2013-5304 Unspecified SQL Injection Vulnerability
61895 TYPO3 Store Locator Extension CVE-2013-5305 Unspecified Cross Site Scripting Vulnerability
61897 TYPO3 Store Locator Extension CVE-2013-5303 Unspecified Security Vulnerability
Exploit / POC
RETIRED: TYPO3 Store Locator Extension Multiple Unspecified Security Vulnerabilities
An attacker can use a browser to exploit these issues. To exploit the cross-site scripting issue an attacker must trick an unsuspecting victim into following a malicious URI.
An attacker can use a browser to exploit these issues. To exploit the cross-site scripting issue an attacker must trick an unsuspecting victim into following a malicious URI.
Solution / Fix
RETIRED: TYPO3 Store Locator Extension Multiple Unspecified Security Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
RETIRED: TYPO3 Store Locator Extension Multiple Unspecified Security Vulnerabilities
References:
References:
- TYPO3 Web Site (TYPO3)