U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search Results (Refine Search)

Search Parameters:
  • Keyword (text search): cpe:2.3:a:typo3:typo3:8.3.1:*:*:*:*:*:*:*
  • CPE Name Search: true
There are 240 matching records.
Displaying matches 61 through 80.
Vuln ID Summary CVSS Severity
CVE-2010-3605

Cross-site scripting (XSS) vulnerability in the powermail extension 1.5.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Published: September 24, 2010; 5:00:33 PM -0400
V3.x:(not available)
V2.0: 4.3 MEDIUM
CVE-2010-3604

SQL injection vulnerability in the powermail extension 1.5.3 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Published: September 24, 2010; 5:00:33 PM -0400
V3.x:(not available)
V2.0: 7.5 HIGH
CVE-2009-4971

SQL injection vulnerability in the AJAX Chat (vjchat) extension before 0.3.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Published: July 28, 2010; 10:43:41 AM -0400
V3.x:(not available)
V2.0: 7.5 HIGH
CVE-2009-4970

SQL injection vulnerability in the t3m_affiliate extension 0.5.0 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Published: July 28, 2010; 10:43:41 AM -0400
V3.x:(not available)
V2.0: 7.5 HIGH
CVE-2009-4969

SQL injection vulnerability in the Solidbase Bannermanagement (SBbanner) extension 1.0.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Published: July 28, 2010; 10:43:41 AM -0400
V3.x:(not available)
V2.0: 7.5 HIGH
CVE-2009-4968

SQL injection vulnerability in the Event Registration (event_registr) extension 1.0.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Published: July 28, 2010; 10:43:41 AM -0400
V3.x:(not available)
V2.0: 7.5 HIGH
CVE-2009-4967

SQL injection vulnerability in the Car (car) extension before 0.1.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Published: July 28, 2010; 10:43:41 AM -0400
V3.x:(not available)
V2.0: 7.5 HIGH
CVE-2009-4966

SQL injection vulnerability in the AST ZipCodeSearch (ast_addresszipsearch) extension 0.5.4 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Published: July 28, 2010; 10:43:41 AM -0400
V3.x:(not available)
V2.0: 7.5 HIGH
CVE-2009-4965

SQL injection vulnerability in the AIRware Lexicon (air_lexicon) extension 0.0.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Published: July 28, 2010; 10:43:41 AM -0400
V3.x:(not available)
V2.0: 7.5 HIGH
CVE-2009-4963

Cross-site scripting (XSS) vulnerability in the Commerce extension before 0.9.9 for TYPO3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

Published: July 28, 2010; 10:43:41 AM -0400
V3.x:(not available)
V2.0: 3.5 LOW
CVE-2009-4959

SQL injection vulnerability in the T3M E-Mail Marketing Tool (t3m) extension 0.2.4 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Published: July 28, 2010; 10:43:39 AM -0400
V3.x:(not available)
V2.0: 7.5 HIGH
CVE-2009-4956

Cross-site scripting (XSS) vulnerability in the Visitor Tracking (ws_stats) extension before 0.1.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Published: July 22, 2010; 2:30:03 PM -0400
V3.x:(not available)
V2.0: 4.3 MEDIUM
CVE-2009-4955

SQL injection vulnerability in the ultraCards (th_ultracards) extension before 0.5.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Published: July 22, 2010; 2:30:03 PM -0400
V3.x:(not available)
V2.0: 7.5 HIGH
CVE-2009-4954

SQL injection vulnerability in the Versatile Calendar Extension [VCE] (sk_calendar) extension before 0.3.4 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Published: July 22, 2010; 2:30:02 PM -0400
V3.x:(not available)
V2.0: 7.5 HIGH
CVE-2009-4953

Cross-site scripting (XSS) vulnerability in the Userdata Create/Edit (sg_userdata) extension before 0.91.0 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Published: July 22, 2010; 2:30:02 PM -0400
V3.x:(not available)
V2.0: 4.3 MEDIUM
CVE-2009-4952

Directory traversal vulnerability in the Directory Listing (dir_listing) extension 1.1.0 and earlier for TYPO3 allows remote attackers to have an unspecified impact via unknown vectors.

Published: July 22, 2010; 2:30:02 PM -0400
V3.x:(not available)
V2.0: 10.0 HIGH
CVE-2009-4951

Unspecified vulnerability in the ClickStream Analyzer [output] (alternet_csa_out) extension 0.3.0 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown vectors.

Published: July 22, 2010; 2:30:02 PM -0400
V3.x:(not available)
V2.0: 5.0 MEDIUM
CVE-2009-4950

SQL injection vulnerability in the A21glossary Advanced Output (a21glossary_advanced_output) extension before 0.1.12 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Published: July 22, 2010; 2:30:02 PM -0400
V3.x:(not available)
V2.0: 7.5 HIGH
CVE-2009-4949

SQL injection vulnerability in the Store Locator extension before 1.2.8 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Published: July 22, 2010; 2:30:02 PM -0400
V3.x:(not available)
V2.0: 7.5 HIGH
CVE-2009-4948

Cross-site scripting (XSS) vulnerability in the Store Locator extension before 1.2.8 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Published: July 22, 2010; 2:30:02 PM -0400
V3.x:(not available)
V2.0: 4.3 MEDIUM