![](/assets/img/cve_300x82_sin_bg.png)
CVE-2013-7079 – Debian Security Advisory 2834-1
https://notcve.org/view.php?id=CVE-2013-7079
23 Dec 2013 — Open redirect vulnerability in the OpenID extension in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. Vulnerabilidad de redirección abierta en la extensión de OpenID en TYPO3 4.5.0 a 4.5.31, 4.7.0 a 4.7.16, 6.0.0 a 6.0.11, y 6.1.0 a 6.1.6 permite a atacantes remotos redireccionar usuarios a sitios web arbitrarios y efectuar ataques de phishin... • http://seclists.org/oss-sec/2013/q4/473 • CWE-20: Improper Input Validation •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2013-7080 – Debian Security Advisory 2834-1
https://notcve.org/view.php?id=CVE-2013-7080
23 Dec 2013 — The creating record functionality in Extension table administration library (feuser_adminLib.inc) in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, and 6.0.0 through 6.0.11 allows remote attackers to write to arbitrary fields in the configuration database table via crafted links, aka "Mass Assignment." La funcionalidad de creación de registros en la tabla de administración de la librería (feuser_adminLib.inc) Extension en TYPO3 4.5.0 a 4.5.31, 4.7.0 a 4.7.16, y 6.0.0 a 6.0.11 permite a atacantes remotos ... • http://seclists.org/oss-sec/2013/q4/473 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2013-7073 – Debian Security Advisory 2834-1
https://notcve.org/view.php?id=CVE-2013-7073
23 Dec 2013 — The Content Editing Wizards component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 does not check permissions, which allows remote authenticated editors to read arbitrary TYPO3 table columns via unspecified parameters. El componente Content Editing Wizards para TYPO3 v4.5.0 hasta v4.5.31, v4.7.0 hasta v4.7.16, v6.0.0 hasta v6.0.11, y v6.1.0 hasta v6.1.6 no comprueba los permisos, lo que permite a los editores remotos autenticados leer columnas de tablas ... • http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00028.html • CWE-264: Permissions, Privileges, and Access Controls •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2013-7075 – Debian Security Advisory 2834-1
https://notcve.org/view.php?id=CVE-2013-7075
23 Dec 2013 — The Content Editing Wizards component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 allows remote authenticated backend users to unserialize arbitrary PHP objects, delete arbitrary files, and possibly have other unspecified impacts via an unspecified parameter, related to a "missing signature." El componente Content Editing Wizards para TYPO3 v4.5.0 hasta v4.5.31, v4.7.0 hasta v4.7.16, v6.0.0 hasta v6.0.11, y v6.1.0 hasta v6.1.6 permite a usuarios del bac... • http://seclists.org/oss-sec/2013/q4/473 • CWE-310: Cryptographic Issues •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2013-7081 – Debian Security Advisory 2834-1
https://notcve.org/view.php?id=CVE-2013-7081
23 Dec 2013 — The (old) Form Content Element component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 allows remote authenticated editors to generate arbitrary HMAC signatures and bypass intended access restrictions via unspecified vectors. El (antiguo) componente Form Content Element en TYPO3 4.5.0 a 4.5.31, 4.7.0 a 4.7.16, 6.0.0 a 6.0.11, y 6.1.0 a 6.1.6 permite a editores autenticados remotamente generar firmas HMAC arbitrarias y sortear restricciones de acceso inten... • http://seclists.org/oss-sec/2013/q4/473 • CWE-264: Permissions, Privileges, and Access Controls •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2013-7077
https://notcve.org/view.php?id=CVE-2013-7077
21 Dec 2013 — Cross-site scripting (XSS) vulnerability in the Backend User Administration Module in TYPO3 6.0.x before 6.0.12 and 6.1.x before 6.1.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad cross-site scripting (XSS) en Backend User Administration Module de TYPO3 6.0.x anteriores a 6.0.12 y 6.1.x anteriores a 6.1.7 permite a atacantes remotos inyectar script web o HTML de forma arbitraria a través de vectores no especificados. • http://osvdb.org/100884 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2013-7076 – Debian Security Advisory 2834-1
https://notcve.org/view.php?id=CVE-2013-7076
21 Dec 2013 — Cross-site scripting (XSS) vulnerability in Extension Manager in TYPO3 4.5.x before 4.5.32 and 4.7.x before 4.7.17 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad cross-site scripting (XSS) en Extension Manager de TYPO3 4.5.x anteriores a 4.5.32 y 4.7.x anteriores a 4.7.17 permite a atacantes remotos inyectar script web o HTML de forma arbitraria a través de vectores no especificados. Several vulnerabilities were discovered in TYPO3, a content managemen... • http://osvdb.org/100883 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2013-7074 – Debian Security Advisory 2834-1
https://notcve.org/view.php?id=CVE-2013-7074
21 Dec 2013 — Multiple cross-site scripting (XSS) vulnerabilities in Content Editing Wizards in TYPO3 4.5.x before 4.5.32, 4.7.x before 4.7.17, 6.0.x before 6.0.12, 6.1.x before 6.1.7, and the development versions of 6.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters. Múltiples vulnerabilidades de cross-site scripting (XSS) en Content Editing Wizards en TYPO3 4.5.x anteriores a 4.5.32, 4.7.x anteriores a 4.7.17, 6.0.x anteriores a 6.0.12, 6.1.x anteriores a 6.1.7, y las... • http://osvdb.org/100881 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2012-6144
https://notcve.org/view.php?id=CVE-2012-6144
01 Jul 2013 — SQL injection vulnerability in the Backend History module in TYPO3 4.5.x before 4.5.21, 4.6.x before 4.6.14, and 4.7.x before 4.7.6 allows remote authenticated backend users to execute arbitrary SQL commands via unspecified vectors. Vulnerabilidad de inyección SQL en el módulo BackEnd History en TYPO3 4.5.x anterior a 4.5.21, 4.6.x anterior a 4.6.14, y 4.7.x anterior a 4.7.6, permite a usuarios del backend autenticados remotamente inyectar comandos SQL arbitrarios a través de vectores no especificados. • http://osvdb.org/87115 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2012-6145
https://notcve.org/view.php?id=CVE-2012-6145
01 Jul 2013 — Cross-site scripting (XSS) vulnerability in the Backend History module in TYPO3 4.5.x before 4.5.21, 4.6.x before 4.6.14, and 4.7.x before 4.7.6 allows remote authenticated backend users to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad XSS en el módulo BackEnd History en TYPO3 4.5.x anterior a 4.5.21, 4.6.x anterior a 4.6.14, y 4.7.x anterior a 4.7.6, permite a usuarios del backend autenticados remotamente inyectar secuencias de comandos web o HTML arbitrarios a través de vecto... • http://osvdb.org/87116 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •