Vulnerability index

Browse CVEs

226 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sql Frontend Extension HIGH 7.5
CVE-2008-3052

Unspecified vulnerability in the SQL Frontend (mh_omsqlio) extension 1.0.11 and earlier for TYPO3 allows remote attackers to cause a denial of servic…

Fix: after 1.0.11
Fix from $1,950 2008-07-07
Sql Frontend Extension HIGH 7.5
CVE-2008-3053

SQL injection vulnerability in the SQL Frontend (mh_omsqlio) extension 1.0.11 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL …

Fix: after 1.0.11
Fix from $1,950 2008-07-07
Branchenbuch Extension HIGH 7.5
CVE-2008-3054

SQL injection vulnerability in the Branchenbuch (aka Yellow Pages o (mh_branchenbuch) extension 0.8.1 and earlier for TYPO3 allows remote attackers t…

Fix: after 0.8.1
Fix from $1,950 2008-07-07
Support View Extension HIGH 7.5
CVE-2008-3055

SQL injection vulnerability in the Support view (ext_tbl) extension 0.0.102 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL co…

Fix: after 0.0.102
Fix from $1,950 2008-07-07
Codeon Petition Extension HIGH 7.5
CVE-2008-3056

SQL injection vulnerability in the Codeon Petition (cd_petition) extension 0.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary S…

Fix: after 0.0.2
Fix from $1,950 2008-07-07
Dam Frontend Extension MEDIUM 5.0
CVE-2008-3040

Unspecified vulnerability in the DAM Frontend (dam_frontend) extension 0.1.0 and earlier for TYPO3 allows remote attackers to obtain sensitive inform…

Fix: after 0.1.0
Fix from $1,600 2008-07-07
Pdf Generator 2 Extension MEDIUM 5.0
CVE-2008-3049

The PDF Generator 2 (pdf_generator2) extension 0.5.0 and earlier for TYPO3 allows attackers to obtain sensitive information via unspecified vectors.

Fix: after 0.5.0
Fix from $1,600 2008-07-07
Pdf Generator 2 Extension MEDIUM 5.0
CVE-2008-3050

Unspecified vulnerability in the PDF Generator 2 (pdf_generator2) extension 0.5.0 and earlier for TYPO3 allows attackers to cause a denial of service…

Fix: after 0.5.0
Fix from $1,600 2008-07-07
Sg Zfelib HIGH 7.5
CVE-2008-2489

SQL injection vulnerability in the Library for Frontend Plugins (aka sg_zfelib) extension 1.1.512 and earlier for TYPO3 allows remote attackers to ex…

Fix: after 1.1.512
Fix from $1,950 2008-05-28
Air Filemanager HIGH 10.0
CVE-2008-2345

Unspecified vulnerability in the air_filemanager 0.6.0 and earlier extension for TYPO3 allows remote attackers to execute arbitrary PHP code via unsp…

Fix: after 0.6.0
Fix from $1,950 2008-05-19
Sr Feuser Register Extension HIGH 7.5
CVE-2008-2275

Unspecified vulnerability in sr_feuser_register 1.4.0, 1.6.0, 2.2.1 to 2.2.7, 2.3.0 to 2.3.6, 2.4.0, and 2.5.0 to 2.5.9 extension for TYPO3 allows re…

Patch available
Fix from $1,950 2008-05-16
TYPO3 MEDIUM 6.5
CVE-2007-6381

SQL injection vulnerability in the indexed_search system extension in TYPO3 3.x, 4.0 through 4.0.7, and 4.1 through 4.1.3 allows remote authenticated…

Patch available
Fix from $1,600 2007-12-15
TYPO3 HIGH 7.5
CVE-2007-1081

The start function in class.t3lib_formmail.php in TYPO3 before 4.0.5, 4.1beta, and 4.1RC1 allows attackers to inject arbitrary email headers via unkn…

Fix: after 4.1
Fix from $1,950 2007-02-22
TYPO3 HIGH 7.5
CVE-2006-6690EPSS 6%

rtehtmlarea/pi1/class.tx_rtehtmlarea_pi1.php in Typo3 4.0.0 through 4.0.3, 3.7 and 3.8 with the rtehtmlarea extension, and 4.1 beta allows remote aut…

Patch available
Fix from $1,950 2006-12-21
TYPO3 MEDIUM 5.0
CVE-2006-0327

TYPO3 3.7.1 allows remote attackers to obtain sensitive information via a direct request to (1) thumbs.php, (2) showpic.php, or (3) tables.php, which…

No fix yet
Fix from $1,600 2006-01-21
TYPO3 HIGH 7.5
CVE-2005-4875

TYPO3 3.8.0 and earlier allows remote attackers to obtain sensitive information via a direct request to misc/phpcheck/, which invokes the phpinfo fun…

Fix: after 3.8.0
Fix from $1,950 2005-12-31