TYPO3 Formhandler Extension Multiple Security Vulnerabilities
BID:61652
Info
TYPO3 Formhandler Extension Multiple Security Vulnerabilities
| Bugtraq ID: | 61652 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 05 2013 12:00AM |
| Updated: | Aug 05 2013 12:00AM |
| Credit: | Georg Ringer and Franz G. Jahn of TYPO3 security team |
| Vulnerable: |
Typo3 Formhandler 1.6 |
| Not Vulnerable: |
Typo3 Formhandler 1.6.1 |
Discussion
TYPO3 Formhandler Extension Multiple Security Vulnerabilities
The Formhandler extension for TYPO3 is prone to multiple security vulnerabilities, including:
1. An unspecified arbitrary code-execution vulnerability
2. An unspecified SQL-injection vulnerability
3. An unspecified authentication-bypass vulnerability
Attackers can exploit these issues to bypass certain security restrictions, execute arbitrary code and modify the logic of SQL queries. Other attacks may also be possible.
Formhandler 1.6.0 is vulnerable; other versions may also be affected.
The Formhandler extension for TYPO3 is prone to multiple security vulnerabilities, including:
1. An unspecified arbitrary code-execution vulnerability
2. An unspecified SQL-injection vulnerability
3. An unspecified authentication-bypass vulnerability
Attackers can exploit these issues to bypass certain security restrictions, execute arbitrary code and modify the logic of SQL queries. Other attacks may also be possible.
Formhandler 1.6.0 is vulnerable; other versions may also be affected.
Exploit / POC
TYPO3 Formhandler Extension Multiple Security Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.