2 results (0.003 seconds)

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 0

Directory traversal vulnerability in the wt_gallery extension 2.5.0 and earlier for TYPO3 allows remote attackers to read arbitrary image files and determine directory structure via unspecified vectors. Vulnerabilidad de salto de directorio en la extensión wt_gallery v2.5.0 y anteriores para TYPO3 permite a atacantes remotos leer ficheros de imagen de forma arbitraria y determinar la estructura del directorio a través de vectores sin especificar. • http://osvdb.org/45050 http://secunia.com/advisories/30217 http://typo3.org/teams/security/security-bulletins/typo3-20080513-1 http://www.securityfocus.com/bid/29182 https://exchange.xforce.ibmcloud.com/vulnerabilities/42364 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 4.3EPSS: 0%CPEs: 2EXPL: 0

Cross-site scripting (XSS) vulnerability in the WT Gallery (aka wt_gallery) extension 2.6.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de secuencia de comandos en sitios cruzados (XSS) en la extensión WT Gallery (también conocida como wt_gallery) versiones 2.6.2 y anteriores para TYPO3, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de vectores no especificados. • http://secunia.com/advisories/30217 http://typo3.org/teams/security/security-bulletins/typo3-20080513-1 http://www.securityfocus.com/bid/29182 https://exchange.xforce.ibmcloud.com/vulnerabilities/42363 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •