
CVE-2009-4396
https://notcve.org/view.php?id=CVE-2009-4396
22 Dec 2009 — SQL injection vulnerability in the Diocese of Portsmouth Resources Database (pd_resources) extension 0.1.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. Vulnerabilidad de inyección SQL de la extensión Diocese of Portsmouth Resources Database (pd_resources) v0.1.1 y anteriores para TYPO3 permite a atacantes remotos ejecutar comandos SQL a través de vectores sin especificar. • http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-020 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2009-4397
https://notcve.org/view.php?id=CVE-2009-4397
22 Dec 2009 — Cross-site scripting (XSS) vulnerability in the Diocese of Portsmouth Resources Database (pd_resources) extension 0.1.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en la extensión Diocese of Portsmouth Resources Database (pd_resources) v0.1.1 y anteriores para TYPO3 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de vectores sin especificar. • http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-020 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2009-4398
https://notcve.org/view.php?id=CVE-2009-4398
22 Dec 2009 — Cross-site scripting (XSS) vulnerability in the Parish of the Holy Spirit Religious Art Gallery (hs_religiousartgallery) extension 0.1.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en la extensión de Parish of the Holy Spirit Religious Art Gallery (hs_religiousartgallery)v0.1.2 y anteriores para TYPO3 permite a atacantes remotos inyectar secuencias de comandos web o HTML de for... • http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-020 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2009-4399
https://notcve.org/view.php?id=CVE-2009-4399
22 Dec 2009 — SQL injection vulnerability in the Parish of the Holy Spirit Religious Art Gallery (hs_religiousartgallery) extension 0.1.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. Vulnerabilidad de inyección SQL en la extensión Parish of the Holy Spirit Religious Art Gallery (hs_religiousartgallery) v0.1.2 y anteriores para TYPO3 permite a atacantes remotos ejecutar comandos SQL de forma arbitraria a través de vectores sin especificar. • http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-020 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2009-4400
https://notcve.org/view.php?id=CVE-2009-4400
22 Dec 2009 — Cross-site scripting (XSS) vulnerability in the Parish Administration Database (ste_parish_admin) extension 0.1.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en la extension de administración de bases de datos v0.1.3 y anteriores de Parish (ste_parish_admin) para TYPO3 permite a atacantes remotos inyectar secuencias de comandos web o HTML de forma arbitraria a través de vectore... • http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-020 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2009-4401
https://notcve.org/view.php?id=CVE-2009-4401
22 Dec 2009 — SQL injection vulnerability in the Parish Administration Database (ste_parish_admin) extension 0.1.3 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. Vulnerabilidad de inyección SQL en la administración de la extensión v0.1.3 y anteriores de la base de datos de Parish (ste_parish_admin) para TYPO3 permite a atacantes remotos ejecutar comandos arbitrarios SQL a través de vectores sin especificar. • http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-020 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2009-4336
https://notcve.org/view.php?id=CVE-2009-4336
17 Dec 2009 — Cross-site scripting (XSS) vulnerability in the Diocese of Portsmouth Calendar (pd_calendar) extension 0.4.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Una vulnerabilidad de ejecución de comandos en sitios cruzados (XSS) en la extensión 'Calendario de la Diocesis de Portsmouth' (pd_calendar) v0.4.1 y anteriores para TYPO3 permite a atacantes remotos inyectar HTML o scripts web a través de vectores no especificados. • http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-020 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2009-4337
https://notcve.org/view.php?id=CVE-2009-4337
17 Dec 2009 — SQL injection vulnerability in the Diocese of Portsmouth Calendar (pd_calendar) extension 0.4.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors, a different issue than CVE-2008-6691. Una vulnerabilidad de inyección SQL en la extensión 'Diocese of Portsmouth Calendar' (pd_calendar) v0.4.1 y anteriores para TYPO3 permite a atacantes remotos ejecutar comandos SQL a través de vectores desconocidos. Se trata de una vulnerabilidad diferente a CVE-2008-6691. • http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-020 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2008-7152 – Specimen Image Database - 'client.php' Remote File Inclusion
https://notcve.org/view.php?id=CVE-2008-7152
01 Sep 2009 — Multiple PHP remote file inclusion vulnerabilities in Specimen Image Database (SID), when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the dir parameter to (1) client.php or (2) taxonservice.php. Múltiples vulnerabilidades de inclusión remota en Specimen Image Database (SID), cuando register_globals es activado, permite a atacantes remotos ejecutar código PHP a su elección a través de una URL en el parámetro dir en (1) client.php o (2) taxonservice.php. • https://www.exploit-db.com/exploits/2576 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2008-6692
https://notcve.org/view.php?id=CVE-2008-6692
10 Apr 2009 — SQL injection vulnerability in Diocese of Portsmouth Training Courses (pd_trainingcourses) extension 0.1.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors. Vulnerabilidad de inyección SQL en Diocese of Portsmouth Training Courses (pd_trainingcourses), extensión v0.1.1 para TYPO3, permite a atacantes remotos ejecutar comandos SQL de su elección a través de vectores desconocidos. • http://osvdb.org/46389 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •