National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database

Search Results (Refine Search)

Search Parameters:
  • Contains Software Flaws (CVE)
  • CPE Product Version: cpe:/a:typo3:typo3:8.7.4
There are 225 matching records.
Displaying matches 61 through 80.
Vuln ID Summary CVSS Severity
CVE-2009-4952

Directory traversal vulnerability in the Directory Listing (dir_listing) extension 1.1.0 and earlier for TYPO3 allows remote attackers to have an unspecified impact via unknown vectors.

Published: July 22, 2010; 02:30:02 PM -04:00
    V2: 10.0 HIGH
CVE-2009-4951

Unspecified vulnerability in the ClickStream Analyzer [output] (alternet_csa_out) extension 0.3.0 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown vectors.

Published: July 22, 2010; 02:30:02 PM -04:00
    V2: 5.0 MEDIUM
CVE-2009-4950

SQL injection vulnerability in the A21glossary Advanced Output (a21glossary_advanced_output) extension before 0.1.12 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Published: July 22, 2010; 02:30:02 PM -04:00
    V2: 7.5 HIGH
CVE-2009-4949

SQL injection vulnerability in the Store Locator extension before 1.2.8 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Published: July 22, 2010; 02:30:02 PM -04:00
    V2: 7.5 HIGH
CVE-2009-4948

Cross-site scripting (XSS) vulnerability in the Store Locator extension before 1.2.8 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Published: July 22, 2010; 02:30:02 PM -04:00
    V2: 4.3 MEDIUM
CVE-2010-2131

SQL injection vulnerability in the Calendar Base (cal) extension before 1.3.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via iCalendar data.

Published: June 02, 2010; 02:30:01 PM -04:00
    V2: 7.5 HIGH
CVE-2009-4804

Cross-site scripting (XSS) vulnerability in the Calendar Base (cal) extension before 1.1.1 for TYPO3, when Internet Explorer 6 is used, allows remote attackers to inject arbitrary web script or HTML via "search parameters."

Published: April 23, 2010; 10:30:00 AM -04:00
    V2: 4.3 MEDIUM
CVE-2009-4803

SQL injection vulnerability in the Accessibility Glossary (a21glossary) extension 0.4.10 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Published: April 23, 2010; 10:30:00 AM -04:00
    V2: 7.5 HIGH
CVE-2009-4802

SQL injection vulnerability in the Flat Manager (flatmgr) extension before 1.9.16 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Published: April 23, 2010; 10:30:00 AM -04:00
    V2: 7.5 HIGH
CVE-2010-1218

Cross-site scripting (XSS) vulnerability in the mm_forum extension 1.8.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Published: March 30, 2010; 07:30:00 PM -04:00
    V2: 4.3 MEDIUM
CVE-2009-4740

Directory traversal vulnerability in the Webesse E-Card (ws_ecard) extension 1.0.2 and earlier for TYPO3 has unspecified impact and remote attack vectors.

Published: March 26, 2010; 04:30:00 PM -04:00
    V2: 7.5 HIGH
CVE-2010-1027

SQL injection vulnerability in the Meet Travelmates (travelmate) extension 0.1.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Published: March 19, 2010; 03:00:01 PM -04:00
    V2: 7.5 HIGH
CVE-2010-1026

SQL injection vulnerability in the CleanDB - DBAL (tmsw_cleandb) extension 2.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Published: March 19, 2010; 03:00:01 PM -04:00
    V2: 7.5 HIGH
CVE-2010-1025

Cross-site scripting (XSS) vulnerability in the TGM-Newsletter (tgm_newsletter) extension 0.0.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Published: March 19, 2010; 03:00:01 PM -04:00
    V2: 4.3 MEDIUM
CVE-2010-1024

SQL injection vulnerability in the TGM-Newsletter (tgm_newsletter) extension 0.0.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Published: March 19, 2010; 03:00:01 PM -04:00
    V2: 7.5 HIGH
CVE-2010-1022

The TYPO3 Security - Salted user password hashes (t3sec_saltedpw) extension before 0.2.13 for TYPO3 allows remote attackers to bypass authentication via unspecified vectors.

Published: March 19, 2010; 03:00:00 PM -04:00
    V2: 7.5 HIGH
CVE-2010-1021

Cross-site scripting (XSS) vulnerability in the Typo3 Quixplorer (t3quixplorer) extension before 1.7.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Published: March 19, 2010; 03:00:00 PM -04:00
    V2: 4.3 MEDIUM
CVE-2010-1020

Cross-site scripting (XSS) vulnerability in the Simple Gallery (sk_simplegallery) extension 0.0.9 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Published: March 19, 2010; 03:00:00 PM -04:00
    V2: 4.3 MEDIUM
CVE-2010-1019

SQL injection vulnerability in the Simple Gallery (sk_simplegallery) extension 0.0.9 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Published: March 19, 2010; 03:00:00 PM -04:00
    V2: 7.5 HIGH
CVE-2010-1018

SQL injection vulnerability in the Book Reviews (sk_bookreview) extension 0.0.12 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Published: March 19, 2010; 03:00:00 PM -04:00
    V2: 7.5 HIGH