Vulnerability index

Browse CVEs

226 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.0 CVE-2010-3716 The be_user_creation task in TYPO3 4.2.x before 4.2.15 and 4.3.x before 4.3.7 allows remote authenticated users to gain privileges via a crafted POST… TYPO3 Mitigation only Fix from $1,6002010-10-25 MEDIUM 5.0 CVE-2010-3717 The t3lib_div::validEmail function in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 does not properly restrict input to filte… TYPO3 Mitigation only Fix from $1,6002010-10-25 HIGH 7.5 CVE-2009-4969 SQL injection vulnerability in the Solidbase Bannermanagement (SBbanner) extension 1.0.1 for TYPO3 allows remote attackers to execute arbitrary SQL c… Sbanner Mitigation only Fix from $1,9502010-07-28 HIGH 7.5 CVE-2009-4855 SQL injection vulnerability in index.php in TYPO3 4.0 allows remote attackers to execute arbitrary SQL commands via the showUid parameter. NOTE: the … TYPO3 No fix yet Fix from $1,9502010-05-11 MEDIUM 6.8 CVE-2010-1153 PHP remote file inclusion vulnerability in the autoloader in TYPO3 4.3.x before 4.3.3 allows remote attackers to execute arbitrary PHP code via a URL… TYPO3 Mitigation only Fix from $1,6002010-04-20 HIGH 7.5 CVE-2009-4740 Directory traversal vulnerability in the Webesse E-Card (ws_ecard) extension 1.0.2 and earlier for TYPO3 has unspecified impact and remote attack vec… Ws Ecard No fix yet Fix from $1,9502010-03-26 HIGH 7.5 CVE-2010-1006 SQL injection vulnerability in the Brainstorming extension 0.1.8 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via … Brainstorming after 0.1.8 Fix from $1,9502010-03-19 HIGH 7.5 CVE-2009-4703 SQL injection vulnerability in the Webesse Image Gallery (ws_gallery) extension 1.0.4 and earlier for TYPO3 allows remote attackers to execute arbitr… Ws Gallery after 1.0.4 Fix from $1,9502010-03-15 MEDIUM 5.0 CVE-2009-4704 Unspecified vulnerability in the Webesse E-Card (ws_ecard) extension 1.0.2 and earlier for TYPO3 allows remote attackers to obtain sensitive informat… Ws Ecard after 1.0.2 Fix from $1,6002010-03-15 MEDIUM 5.1 CVE-2010-0286 Unspecified vulnerability in the OpenID Identity Authentication extension in TYPO3 4.3.0 allows remote attackers to bypass authentication and gain ac… TYPO3 Patch available Fix from $1,6002010-02-22 HIGH 7.5 CVE-2010-0340 SQL injection vulnerability in the MJS Event Pro (mjseventpro) extension 0.2.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL… Mjseventpro after 0.2.1 Fix from $1,9502010-01-15 HIGH 7.5 CVE-2010-0341 SQL injection vulnerability in the BB Simple Jobs (bb_simplejobs) extension 0.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary … Bb Simplejobs after 0.1.0 Fix from $1,9502010-01-15 HIGH 7.5 CVE-2010-0342 SQL injection vulnerability in the Reports for Job (job_reports) extension 0.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary S… Job Reports after 0.1.0 Fix from $1,9502010-01-15 HIGH 7.5 CVE-2010-0343 SQL injection vulnerability in the Clan Users List (pb_clanlist) extension 0.0.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands … Pb Clanlist Mitigation only Fix from $1,9502010-01-15 HIGH 7.5 CVE-2010-0344 SQL injection vulnerability in the zak_store_management extension 1.0.0 and earlier TYPO3 allows remote attackers to execute arbitrary SQL commands v… Zak Store Management after 1.0.0 Fix from $1,9502010-01-15 HIGH 7.5 CVE-2010-0337 SQL injection vulnerability in the tt_news Mail alert (dl3_tt_news_alerts) extension 0.2.0 and earlier for TYPO3 allows remote attackers to execute a… Dl3 Tt News Alerts after 0.2.0 Fix from $1,9502010-01-15 HIGH 7.5 CVE-2010-0338 SQL injection vulnerability in the TT_Products editor (ttpedit) extension 0.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQ… Ttpedit Mitigation only Fix from $1,9502010-01-15 HIGH 7.5 CVE-2010-0339 SQL injection vulnerability in the User Links (vm19_userlinks) extension 0.1.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL… Vm19 Userlinks after 0.1.1 Fix from $1,9502010-01-15 MEDIUM 5.0 CVE-2010-0336 Unspecified vulnerability in the kiddog_mysqldumper (kiddog_mysqldumper) extension 0.0.3 and earlier for TYPO3 allows remote attackers to obtain sens… Kiddog Mysqldumper after 0.0.3 Fix from $1,6002010-01-15 HIGH 7.5 CVE-2009-4392 SQL injection vulnerability in the XDS Staff List (xds_staff) extension 0.0.3 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL … Xds Staff after 0.0.3 Fix from $1,9502009-12-22 HIGH 8.5 CVE-2009-3631 The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2, when the DAM extension or … TYPO3 after 4.0.12 Fix from $1,9502009-11-02 MEDIUM 6.8 CVE-2009-3635 The Install Tool subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote attacker… TYPO3 after 4.0.12 Fix from $1,6002009-11-02 MEDIUM 6.5 CVE-2009-3632 SQL injection vulnerability in the traditional frontend editing feature in the Frontend Editing subcomponent in TYPO3 4.0.13 and earlier, 4.1.x befor… TYPO3 after 4.0.13 Fix from $1,6002009-11-02 MEDIUM 5.5 CVE-2009-3630 The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote authenticated… TYPO3 after 4.0.12 Fix from $1,6002009-11-02 HIGH 7.5 CVE-2008-6690 Unspecified vulnerability in nepa-design.de Spam Protection (nd_antispam) extension 1.0.3 for TYPO3 allows remote attackers to modify configuration v… Nd Antispam Mitigation only Fix from $1,9502009-04-10 HIGH 7.8 CVE-2008-6630 Directory traversal vulnerability in the wt_gallery extension 2.5.0 and earlier for TYPO3 allows remote attackers to read arbitrary image files and d… Wt Gallery after 2.5.0 Fix from $1,9502009-04-07 HIGH 7.5 CVE-2008-6595 SQL injection vulnerability in the pmk_rssnewsexport extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified ve… Pmk Rssnewsexport Extension Mitigation only Fix from $1,9502009-04-03 HIGH 7.5 CVE-2008-6459 SQL injection vulnerability in the auto BE User Registration (autobeuser) extension 0.0.2 and earlier for TYPO3 allows remote attackers to execute ar… Autobeuser after 0.0.2 Fix from $1,9502009-03-13 MEDIUM 5.0 CVE-2009-0815EPSS 42% The jumpUrl mechanism in class.tslib_fe.php in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 before 4.2.6, and 4.3alpha1 leaks… TYPO3 Patch available Fix from $1,6002009-03-05 HIGH 7.5 CVE-2008-6344 SQL injection vulnerability in the TU-Clausthal Staff (tuc_staff) 0.3.0 and earlier extension for TYPO3 allows remote attackers to execute arbitrary … Tu Clausthal Staff after 0.3.0 Fix from $1,9502009-02-27