Vulnerability index

Browse CVEs

226 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wec Discussion Forum HIGH 7.5
CVE-2008-6145

Multiple SQL injection vulnerabilities in the WEC Discussion Forum (wec_discussion) extension 1.7.0 and earlier for TYPO3 allow remote attackers to e…

Fix: after 1.7.0
Fix from $1,950 2009-02-16
TYPO3 HIGH 10.0
CVE-2009-0258

The Indexed Search Engine (indexed_search) system extension in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote …

Mitigation only
Fix from $1,950 2009-01-22
TYPO3 HIGH 7.5
CVE-2009-0256

Session fixation vulnerability in the authentication library in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote…

Mitigation only
Fix from $1,950 2009-01-22
TYPO3 HIGH 7.5
CVE-2009-0255EPSS 9%

The System extension Install tool in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 creates the encryption key with an insuf…

Fix: 4.0.10 / 4.1.8+
Fix from $1,950 2009-01-22
Dictionary Extension HIGH 10.0
CVE-2008-5801

Unspecified vulnerability in the Dictionary (rtgdictionary) extension 0.1.9 and earlier for TYPO3 allows attackers to execute arbitrary code via unkn…

Fix: after 0.1.9
Fix from $1,950 2008-12-31
Eluna Page Comments Extension HIGH 7.5
CVE-2008-5796

SQL injection vulnerability in the eluna Page Comments (eluna_pagecomments) extension 1.1.2 and earlier for TYPO3 allows remote attackers to execute …

Fix: after 1.1.2
Fix from $1,950 2008-12-31
Advcalendar Extension HIGH 7.5
CVE-2008-5797

SQL injection vulnerability in the advCalendar extension 0.3.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via un…

Fix: after 0.3.1
Fix from $1,950 2008-12-31
Cms Poll System Extension HIGH 7.5
CVE-2008-5798

SQL injection vulnerability in the CMS Poll system (cms_poll) extension before 0.1.1 for TYPO3 allows remote attackers to execute arbitrary SQL comma…

Fix: after 0.1.0
Fix from $1,950 2008-12-31
Fsmi People HIGH 7.5
CVE-2008-5800

SQL injection vulnerability in the Wir ber uns [sic] (fsmi_people) extension 0.0.24 and earlier for TYPO3 allows remote attackers to execute arbitrar…

Fix: after 0.0.24
Fix from $1,950 2008-12-31
Commerce Extension HIGH 7.5
CVE-2008-5609

SQL injection vulnerability in the Commerce extension 0.9.6 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspe…

Fix: after 0.9.6
Fix from $1,950 2008-12-17
File List Extension MEDIUM 5.0
CVE-2008-5096

Unspecified vulnerability in the TYPO3 File List (file_list) extension 0.2.1 and earlier allows remote attackers to obtain sensitive information via …

Fix: after 0.2.1
Fix from $1,600 2008-11-14
Another Backend Login HIGH 7.5
CVE-2008-5087

SQL injection vulnerability in TYPO3 Another Backend Login (wrg_anotherbelogin) extension before 0.0.4 allows remote attackers to execute arbitrary S…

Fix: after 0.0.3
Fix from $1,950 2008-11-14
Simplesurvey HIGH 7.5
CVE-2008-4655

SQL injection vulnerability in the Simple survey (simplesurvey) 1.7.0 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQ…

Fix: after 1.7.0
Fix from $1,950 2008-10-22
Frontend Users View HIGH 7.5
CVE-2008-4656

SQL injection vulnerability in the Frontend Users View (feusersview) 0.1.6 and earlier extension for TYPO3 allows remote attackers to execute arbitra…

Fix: after 0.1.6
Fix from $1,950 2008-10-22
Econda Plugin HIGH 7.5
CVE-2008-4657

SQL injection vulnerability in the Econda Plugin (econda) 0.0.2 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL comm…

Fix: after 0.0.2
Fix from $1,950 2008-10-22
Jobcontrol HIGH 7.5
CVE-2008-4658

SQL injection vulnerability in the JobControl (dmmjobcontrol) 1.15.4 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL…

Fix: after 1.15.4
Fix from $1,950 2008-10-22
Mannschaftsliste HIGH 7.5
CVE-2008-4659

SQL injection vulnerability in the Mannschaftsliste (kiddog_playerlist) 1.0.3 and earlier extension for TYPO3 allows remote attackers to execute arbi…

Fix: after 1.0.3
Fix from $1,950 2008-10-22
M1 Intern HIGH 7.5
CVE-2008-4660

SQL injection vulnerability in the M1 Intern (m1_intern) 1.0.0 extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unsp…

No fix yet
Fix from $1,950 2008-10-22
Secure Directory HIGH 10.0
CVE-2008-4188

Unspecified vulnerability in the TYPO3 Secure Directory (kw_secdir) extension before 1.0.2 allows remote attackers to execute arbitrary code via unkn…

Fix: after 1.0.1
Fix from $1,950 2008-09-23
Dam Frontend Extension HIGH 10.0
CVE-2008-3042

Unspecified vulnerability in the DAM Frontend (dam_frontend) extension 0.1.0 and earlier for TYPO3 has unknown impact and attack vectors related to "…

Fix: after 0.1.0
Fix from $1,950 2008-07-07
Address Directory HIGH 7.5
CVE-2008-3038

SQL injection vulnerability in the Address Directory (sp_directory) extension 0.2.10 and earlier for TYPO3 allows remote attackers to execute arbitra…

Fix: after 0.2.10
Fix from $1,950 2008-07-07
Dam Frontend Extension HIGH 7.5
CVE-2008-3039

SQL injection vulnerability in the DAM Frontend (dam_frontend) extension 0.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL…

Fix: after 0.1.0
Fix from $1,950 2008-07-07
Dam Frontend Extension HIGH 7.5
CVE-2008-3041

Unspecified vulnerability in the DAM Frontend (dam_frontend) extension 0.1.0 and earlier for TYPO3 has unknown impact and attack vectors related to "…

Fix: after 0.1.0
Fix from $1,950 2008-07-07
Wec Discussion Forum HIGH 7.5
CVE-2008-3043

Unspecified vulnerability in the WEC Discussion Forum (wec_discussion) extension 1.6.2 and earlier for TYPO3 allows attackers to execute arbitrary co…

Fix: after 1.6.2
Fix from $1,950 2008-07-07
News Calendar Extension HIGH 7.5
CVE-2008-3044

SQL injection vulnerability in the News Calendar (newscalendar) extension 1.0.7 and earlier for TYPO3 allows remote attackers to execute arbitrary SQ…

Fix: after 1.0.7
Fix from $1,950 2008-07-07
Industry Database HIGH 7.5
CVE-2008-3045

Unspecified vulnerability in the Industry Database (aka Branchendatenbank pro_industrydb) extension 1.0.0 and earlier for TYPO3 has unknown impact an…

Fix: after 1.0.0
Fix from $1,950 2008-07-07
Packman Extension HIGH 7.5
CVE-2008-3046

Incomplete blacklist vulnerability in the Packman (kb_packman) extension 0.2.1 and earlier for TYPO3 has unknown impact and attack vectors.

Fix: after 0.2.1
Fix from $1,950 2008-07-07
Kb Unpack Extension HIGH 7.5
CVE-2008-3047

Incomplete blacklist vulnerability in the KB Unpack (kb_unpack) extension 0.1.0 and earlier for TYPO3 has unknown impact and attack vectors.

Fix: after 0.1.0
Fix from $1,950 2008-07-07
Pdf Generator 2 Extension HIGH 7.5
CVE-2008-3048

Unspecified vulnerability in the PDF Generator 2 (pdf_generator2) extension 0.5.0 and earlier for TYPO3 has unknown impact and attack vectors related…

Fix: after 0.5.0
Fix from $1,950 2008-07-07
Pinboard Extension HIGH 7.5
CVE-2008-3051

SQL injection vulnerability in the Pinboard extension 0.0.6 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspe…

Fix: after 0.0.6
Fix from $1,950 2008-07-07