TYPO3 Calendar Base Extension Denial of Service Vulnerability
BID:70645
Info
TYPO3 Calendar Base Extension Denial of Service Vulnerability
| Bugtraq ID: | 70645 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-8325 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 17 2014 12:00AM |
| Updated: | Oct 21 2014 12:59AM |
| Credit: | Daniel Hahler and Bernd Schuhmacher |
| Vulnerable: |
Typo3 Calendar Base 1.3.2 Typo3 Calendar Base 1.3.1 Typo3 Calendar Base 1.2.1 Typo3 Calendar Base 1.2 Typo3 Calendar Base 1.1.1 Typo3 Calendar Base 1.1 |
| Not Vulnerable: | |
Discussion
TYPO3 Calendar Base Extension Denial of Service Vulnerability
Calendar Base extension for TYPO3 is prone to a denial-of-service vulnerability because it fails to properly validate user-supplied input.
Successfully exploiting this issue may allow an attacker to cause denial-of-service conditions.
Calendar Base extension for TYPO3 is prone to a denial-of-service vulnerability because it fails to properly validate user-supplied input.
Successfully exploiting this issue may allow an attacker to cause denial-of-service conditions.
Exploit / POC
TYPO3 Calendar Base Extension Denial of Service Vulnerability
An attacker can use a browser to exploit this issue.
An attacker can use a browser to exploit this issue.
Solution / Fix
TYPO3 Calendar Base Extension Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.