Vulnerability index

Browse CVEs

44 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

TYPO3 MEDIUM 6.0
CVE-2010-3716

The be_user_creation task in TYPO3 4.2.x before 4.2.15 and 4.3.x before 4.3.7 allows remote authenticated users to gain privileges via a crafted POST…

Mitigation only
Fix from $1,600 2010-10-25
TYPO3 MEDIUM 5.0
CVE-2010-3717

The t3lib_div::validEmail function in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 does not properly restrict input to filte…

Mitigation only
Fix from $1,600 2010-10-25
Sbanner HIGH 7.5
CVE-2009-4969

SQL injection vulnerability in the Solidbase Bannermanagement (SBbanner) extension 1.0.1 for TYPO3 allows remote attackers to execute arbitrary SQL c…

Mitigation only
Fix from $1,950 2010-07-28
TYPO3 HIGH 7.5
CVE-2009-4855

SQL injection vulnerability in index.php in TYPO3 4.0 allows remote attackers to execute arbitrary SQL commands via the showUid parameter. NOTE: the …

No fix yet
Fix from $1,950 2010-05-11
TYPO3 MEDIUM 6.8
CVE-2010-1153

PHP remote file inclusion vulnerability in the autoloader in TYPO3 4.3.x before 4.3.3 allows remote attackers to execute arbitrary PHP code via a URL…

Mitigation only
Fix from $1,600 2010-04-20
Ws Ecard HIGH 7.5
CVE-2009-4740

Directory traversal vulnerability in the Webesse E-Card (ws_ecard) extension 1.0.2 and earlier for TYPO3 has unspecified impact and remote attack vec…

No fix yet
Fix from $1,950 2010-03-26
Pb Clanlist HIGH 7.5
CVE-2010-0343

SQL injection vulnerability in the Clan Users List (pb_clanlist) extension 0.0.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands …

Mitigation only
Fix from $1,950 2010-01-15
Ttpedit HIGH 7.5
CVE-2010-0338

SQL injection vulnerability in the TT_Products editor (ttpedit) extension 0.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQ…

Mitigation only
Fix from $1,950 2010-01-15
Nd Antispam HIGH 7.5
CVE-2008-6690

Unspecified vulnerability in nepa-design.de Spam Protection (nd_antispam) extension 1.0.3 for TYPO3 allows remote attackers to modify configuration v…

Mitigation only
Fix from $1,950 2009-04-10
Pmk Rssnewsexport Extension HIGH 7.5
CVE-2008-6595

SQL injection vulnerability in the pmk_rssnewsexport extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified ve…

Mitigation only
Fix from $1,950 2009-04-03
TYPO3 HIGH 10.0
CVE-2009-0258

The Indexed Search Engine (indexed_search) system extension in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote …

Mitigation only
Fix from $1,950 2009-01-22
TYPO3 HIGH 7.5
CVE-2009-0256

Session fixation vulnerability in the authentication library in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote…

Mitigation only
Fix from $1,950 2009-01-22
M1 Intern HIGH 7.5
CVE-2008-4660

SQL injection vulnerability in the M1 Intern (m1_intern) 1.0.0 extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unsp…

No fix yet
Fix from $1,950 2008-10-22
TYPO3 MEDIUM 5.0
CVE-2006-0327

TYPO3 3.7.1 allows remote attackers to obtain sensitive information via a direct request to (1) thumbs.php, (2) showpic.php, or (3) tables.php, which…

No fix yet
Fix from $1,600 2006-01-21