Vulnerability index

Browse CVEs

226 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

TYPO3 MEDIUM 6.0
CVE-2010-3716

The be_user_creation task in TYPO3 4.2.x before 4.2.15 and 4.3.x before 4.3.7 allows remote authenticated users to gain privileges via a crafted POST…

Mitigation only
Fix from $1,600 2010-10-25
TYPO3 MEDIUM 5.0
CVE-2010-3717

The t3lib_div::validEmail function in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 does not properly restrict input to filte…

Mitigation only
Fix from $1,600 2010-10-25
Sbanner HIGH 7.5
CVE-2009-4969

SQL injection vulnerability in the Solidbase Bannermanagement (SBbanner) extension 1.0.1 for TYPO3 allows remote attackers to execute arbitrary SQL c…

Mitigation only
Fix from $1,950 2010-07-28
TYPO3 HIGH 7.5
CVE-2009-4855

SQL injection vulnerability in index.php in TYPO3 4.0 allows remote attackers to execute arbitrary SQL commands via the showUid parameter. NOTE: the …

No fix yet
Fix from $1,950 2010-05-11
TYPO3 MEDIUM 6.8
CVE-2010-1153

PHP remote file inclusion vulnerability in the autoloader in TYPO3 4.3.x before 4.3.3 allows remote attackers to execute arbitrary PHP code via a URL…

Mitigation only
Fix from $1,600 2010-04-20
Ws Ecard HIGH 7.5
CVE-2009-4740

Directory traversal vulnerability in the Webesse E-Card (ws_ecard) extension 1.0.2 and earlier for TYPO3 has unspecified impact and remote attack vec…

No fix yet
Fix from $1,950 2010-03-26
Brainstorming HIGH 7.5
CVE-2010-1006

SQL injection vulnerability in the Brainstorming extension 0.1.8 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via …

Fix: after 0.1.8
Fix from $1,950 2010-03-19
Ws Gallery HIGH 7.5
CVE-2009-4703

SQL injection vulnerability in the Webesse Image Gallery (ws_gallery) extension 1.0.4 and earlier for TYPO3 allows remote attackers to execute arbitr…

Fix: after 1.0.4
Fix from $1,950 2010-03-15
Ws Ecard MEDIUM 5.0
CVE-2009-4704

Unspecified vulnerability in the Webesse E-Card (ws_ecard) extension 1.0.2 and earlier for TYPO3 allows remote attackers to obtain sensitive informat…

Fix: after 1.0.2
Fix from $1,600 2010-03-15
TYPO3 MEDIUM 5.1
CVE-2010-0286

Unspecified vulnerability in the OpenID Identity Authentication extension in TYPO3 4.3.0 allows remote attackers to bypass authentication and gain ac…

Patch available
Fix from $1,600 2010-02-22
Mjseventpro HIGH 7.5
CVE-2010-0340

SQL injection vulnerability in the MJS Event Pro (mjseventpro) extension 0.2.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL…

Fix: after 0.2.1
Fix from $1,950 2010-01-15
Bb Simplejobs HIGH 7.5
CVE-2010-0341

SQL injection vulnerability in the BB Simple Jobs (bb_simplejobs) extension 0.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary …

Fix: after 0.1.0
Fix from $1,950 2010-01-15
Job Reports HIGH 7.5
CVE-2010-0342

SQL injection vulnerability in the Reports for Job (job_reports) extension 0.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary S…

Fix: after 0.1.0
Fix from $1,950 2010-01-15
Pb Clanlist HIGH 7.5
CVE-2010-0343

SQL injection vulnerability in the Clan Users List (pb_clanlist) extension 0.0.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands …

Mitigation only
Fix from $1,950 2010-01-15
Zak Store Management HIGH 7.5
CVE-2010-0344

SQL injection vulnerability in the zak_store_management extension 1.0.0 and earlier TYPO3 allows remote attackers to execute arbitrary SQL commands v…

Fix: after 1.0.0
Fix from $1,950 2010-01-15
Dl3 Tt News Alerts HIGH 7.5
CVE-2010-0337

SQL injection vulnerability in the tt_news Mail alert (dl3_tt_news_alerts) extension 0.2.0 and earlier for TYPO3 allows remote attackers to execute a…

Fix: after 0.2.0
Fix from $1,950 2010-01-15
Ttpedit HIGH 7.5
CVE-2010-0338

SQL injection vulnerability in the TT_Products editor (ttpedit) extension 0.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQ…

Mitigation only
Fix from $1,950 2010-01-15
Vm19 Userlinks HIGH 7.5
CVE-2010-0339

SQL injection vulnerability in the User Links (vm19_userlinks) extension 0.1.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL…

Fix: after 0.1.1
Fix from $1,950 2010-01-15
Kiddog Mysqldumper MEDIUM 5.0
CVE-2010-0336

Unspecified vulnerability in the kiddog_mysqldumper (kiddog_mysqldumper) extension 0.0.3 and earlier for TYPO3 allows remote attackers to obtain sens…

Fix: after 0.0.3
Fix from $1,600 2010-01-15
Xds Staff HIGH 7.5
CVE-2009-4392

SQL injection vulnerability in the XDS Staff List (xds_staff) extension 0.0.3 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL …

Fix: after 0.0.3
Fix from $1,950 2009-12-22
TYPO3 HIGH 8.5
CVE-2009-3631

The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2, when the DAM extension or …

Fix: after 4.0.12
Fix from $1,950 2009-11-02
TYPO3 MEDIUM 6.8
CVE-2009-3635

The Install Tool subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote attacker…

Fix: after 4.0.12
Fix from $1,600 2009-11-02
TYPO3 MEDIUM 6.5
CVE-2009-3632

SQL injection vulnerability in the traditional frontend editing feature in the Frontend Editing subcomponent in TYPO3 4.0.13 and earlier, 4.1.x befor…

Fix: after 4.0.13
Fix from $1,600 2009-11-02
TYPO3 MEDIUM 5.5
CVE-2009-3630

The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote authenticated…

Fix: after 4.0.12
Fix from $1,600 2009-11-02
Nd Antispam HIGH 7.5
CVE-2008-6690

Unspecified vulnerability in nepa-design.de Spam Protection (nd_antispam) extension 1.0.3 for TYPO3 allows remote attackers to modify configuration v…

Mitigation only
Fix from $1,950 2009-04-10
Wt Gallery HIGH 7.8
CVE-2008-6630

Directory traversal vulnerability in the wt_gallery extension 2.5.0 and earlier for TYPO3 allows remote attackers to read arbitrary image files and d…

Fix: after 2.5.0
Fix from $1,950 2009-04-07
Pmk Rssnewsexport Extension HIGH 7.5
CVE-2008-6595

SQL injection vulnerability in the pmk_rssnewsexport extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified ve…

Mitigation only
Fix from $1,950 2009-04-03
Autobeuser HIGH 7.5
CVE-2008-6459

SQL injection vulnerability in the auto BE User Registration (autobeuser) extension 0.0.2 and earlier for TYPO3 allows remote attackers to execute ar…

Fix: after 0.0.2
Fix from $1,950 2009-03-13
TYPO3 MEDIUM 5.0
CVE-2009-0815EPSS 42%

The jumpUrl mechanism in class.tslib_fe.php in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 before 4.2.6, and 4.3alpha1 leaks…

Patch available
Fix from $1,600 2009-03-05
Tu Clausthal Staff HIGH 7.5
CVE-2008-6344

SQL injection vulnerability in the TU-Clausthal Staff (tuc_staff) 0.3.0 and earlier extension for TYPO3 allows remote attackers to execute arbitrary …

Fix: after 0.3.0
Fix from $1,950 2009-02-27