National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database

Search Results (Refine Search)

Search Parameters:
  • Contains Software Flaws (CVE)
  • CPE Product Version: cpe:/a:typo3:typo3:8.7.4
There are 225 matching records.
Displaying matches 161 through 180.
Vuln ID Summary CVSS Severity
CVE-2009-4165

SQL injection vulnerability in the simple Glossar (simple_glossar) extension 1.0.3 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Published: December 02, 2009; 12:30:00 PM -05:00
    V2: 7.5 HIGH
CVE-2009-4164

Cross-site scripting (XSS) vulnerability in the simple Glossar (simple_glossar) extension 1.0.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Published: December 02, 2009; 12:30:00 PM -05:00
    V2: 4.3 MEDIUM
CVE-2009-4163

SQL injection vulnerability in the TW Productfinder (tw_productfinder) extension 0.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Published: December 02, 2009; 12:30:00 PM -05:00
    V2: 7.5 HIGH
CVE-2009-4162

Unspecified vulnerability in the DB Integration (wfqbe) extension 1.3.1 and earlier for TYPO3 allows local users to execute arbitrary commands via unspecified vectors.

Published: December 02, 2009; 12:30:00 PM -05:00
    V2: 7.2 HIGH
CVE-2009-4161

Cross-site scripting (XSS) vulnerability in the [AN] Search it! (an_searchit) extension 2.4.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Published: December 02, 2009; 12:30:00 PM -05:00
    V2: 4.3 MEDIUM
CVE-2009-4160

Unspecified vulnerability in the Simple download-system with counter and categories (kk_downloader) extension 1.2.1 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown attack vectors.

Published: December 02, 2009; 12:30:00 PM -05:00
    V2: 5.0 MEDIUM
CVE-2009-4159

Cross-site scripting (XSS) vulnerability in the newsletter configuration feature in the backend module in the Direct Mail (direct_mail) extension 2.6.4 and earlier for TYPO3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

Published: December 02, 2009; 12:30:00 PM -05:00
    V2: 3.5 LOW
CVE-2009-4158

SQL injection vulnerability in the Calendar Base (cal) extension before 1.2.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Published: December 02, 2009; 12:30:00 PM -05:00
    V2: 7.5 HIGH
CVE-2009-3821

Cross-site scripting (XSS) vulnerability in the Apache Solr Search (solr) extension 1.0.0 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Published: October 28, 2009; 06:30:00 AM -04:00
    V2: 4.3 MEDIUM
CVE-2009-3820

SQL injection vulnerability in the Flagbit Filebase (fb_filebase) extension 0.1.0 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Published: October 28, 2009; 06:30:00 AM -04:00
    V2: 7.5 HIGH
CVE-2009-3819

Unspecified vulnerability in the Random Images (maag_randomimage) extension 1.6.4 and earlier for TYPO3 allows remote attackers to execute arbitrary shell commands via unspecified vectors.

Published: October 28, 2009; 06:30:00 AM -04:00
    V2: 10.0 HIGH
CVE-2009-3818

Unspecified vulnerability in the session handling feature in freeCap CAPTCHA (sr_freecap) extension 1.2.0 and earlier for TYPO3 has unknown impact and attack vectors.

Published: October 28, 2009; 06:30:00 AM -04:00
    V2: 10.0 HIGH
CVE-2009-2106

SQL injection vulnerability in the Virtual Civil Services (civserv) extension 4.3.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Published: June 17, 2009; 01:30:00 PM -04:00
    V2: 7.5 HIGH
CVE-2009-2104

Cross-site scripting (XSS) vulnerability in the Modern Guestbook / Commenting System (ve_guestbook) extension 2.7.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Published: June 17, 2009; 01:30:00 PM -04:00
    V2: 4.3 MEDIUM
CVE-2008-6699

Cross-site scripting (XSS) vulnerability in Resource Library (tjs_reslib) 0.1.0 and earlier extension for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

Published: April 10, 2009; 06:00:00 PM -04:00
    V2: 4.3 MEDIUM
CVE-2008-6698

Cross-site scripting (XSS) vulnerability in TARGET-E WorldCup Bets (worldcup) 2.0.0 and earlier extension for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

Published: April 10, 2009; 06:00:00 PM -04:00
    V2: 4.3 MEDIUM
CVE-2008-6697

SQL injection vulnerability in TARGET-E WorldCup Bets (worldcup) 2.0.0 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

Published: April 10, 2009; 06:00:00 PM -04:00
    V2: 7.5 HIGH
CVE-2008-6696

SQL injection vulnerability in Fussballtippspiel (toto) 0.1.1 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

Published: April 10, 2009; 06:00:00 PM -04:00
    V2: 7.5 HIGH
CVE-2008-6695

SQL injection vulnerability in TIMTAB social bookmark icons (timtab_sociable) 2.0.4 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

Published: April 10, 2009; 06:00:00 PM -04:00
    V2: 7.5 HIGH
CVE-2008-6694

SQL injection vulnerability in Random Prayer (ste_prayer) 0.0.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

Published: April 10, 2009; 06:00:00 PM -04:00
    V2: 7.5 HIGH