Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.804206
Category:Web application abuses
Title:TYPO3 Multiple Vulnerabilities (Dec 2013)
Summary:TYPO3 is prone to multiple vulnerabilities.
Description:Summary:
TYPO3 is prone to multiple vulnerabilities.

Vulnerability Insight:
Multiple errors exist in the application:

- Multiple errors exist in Content Editing Wizard, which fails to check user
permissions, properly encode user input and which misses signature for an
input parameter.

- An error exists in Extbase Framework, which returns error messages without
properly encoding.

- An error exists in openid extension, which allows redirection to arbitrary
URL.

- An error exists in form content element, which allows generation of arbitrary
signatures that could be used in a different context.

Vulnerability Impact:
Successful exploitation will allow remote attackers to get sensitive
information or execute arbitrary script code.

Affected Software/OS:
TYPO3 version 4.5.0 to 4.5.31, 4.7.0 to 4.7.16, 6.0.0 to 6.0.11, 6.1.0 to
6.1.6

Solution:
Upgrade to TYPO3 version 4.5.32, 4.7.17, 6.0.12, 6.1.7 or later.

CVSS Score:
6.5

CVSS Vector:
AV:N/AC:L/Au:S/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2013-7073
Debian Security Information: DSA-2834 (Google Search)
http://www.debian.org/security/2014/dsa-2834
http://seclists.org/oss-sec/2013/q4/473
http://seclists.org/oss-sec/2013/q4/487
SuSE Security Announcement: openSUSE-SU-2016:2025 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00028.html
SuSE Security Announcement: openSUSE-SU-2016:2114 (Google Search)
http://lists.opensuse.org/opensuse-updates/2016-08/msg00083.html
SuSE Security Announcement: openSUSE-SU-2016:2169 (Google Search)
http://lists.opensuse.org/opensuse-updates/2016-08/msg00106.html
Common Vulnerability Exposure (CVE) ID: CVE-2013-7074
BugTraq ID: 64245
http://www.securityfocus.com/bid/64245
http://osvdb.org/100881
XForce ISS Database: contenteditingwizards-url-xss(89620)
https://exchange.xforce.ibmcloud.com/vulnerabilities/89620
Common Vulnerability Exposure (CVE) ID: CVE-2013-7075
Common Vulnerability Exposure (CVE) ID: CVE-2013-7078
BugTraq ID: 64239
http://www.securityfocus.com/bid/64239
http://osvdb.org/100885
XForce ISS Database: extbase-actioncontroller-xss(89629)
https://exchange.xforce.ibmcloud.com/vulnerabilities/89629
Common Vulnerability Exposure (CVE) ID: CVE-2013-7079
BugTraq ID: 64252
http://www.securityfocus.com/bid/64252
Common Vulnerability Exposure (CVE) ID: CVE-2013-7081
CopyrightCopyright (C) 2014 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.