
CVE-2013-7080 – Debian Security Advisory 2834-1
https://notcve.org/view.php?id=CVE-2013-7080
23 Dec 2013 — The creating record functionality in Extension table administration library (feuser_adminLib.inc) in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, and 6.0.0 through 6.0.11 allows remote attackers to write to arbitrary fields in the configuration database table via crafted links, aka "Mass Assignment." La funcionalidad de creación de registros en la tabla de administración de la librería (feuser_adminLib.inc) Extension en TYPO3 4.5.0 a 4.5.31, 4.7.0 a 4.7.16, y 6.0.0 a 6.0.11 permite a atacantes remotos ... • http://seclists.org/oss-sec/2013/q4/473 •

CVE-2013-7081 – Debian Security Advisory 2834-1
https://notcve.org/view.php?id=CVE-2013-7081
23 Dec 2013 — The (old) Form Content Element component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 allows remote authenticated editors to generate arbitrary HMAC signatures and bypass intended access restrictions via unspecified vectors. El (antiguo) componente Form Content Element en TYPO3 4.5.0 a 4.5.31, 4.7.0 a 4.7.16, 6.0.0 a 6.0.11, y 6.1.0 a 6.1.6 permite a editores autenticados remotamente generar firmas HMAC arbitrarias y sortear restricciones de acceso inten... • http://seclists.org/oss-sec/2013/q4/473 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2013-7074 – Debian Security Advisory 2834-1
https://notcve.org/view.php?id=CVE-2013-7074
21 Dec 2013 — Multiple cross-site scripting (XSS) vulnerabilities in Content Editing Wizards in TYPO3 4.5.x before 4.5.32, 4.7.x before 4.7.17, 6.0.x before 6.0.12, 6.1.x before 6.1.7, and the development versions of 6.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters. Múltiples vulnerabilidades de cross-site scripting (XSS) en Content Editing Wizards en TYPO3 4.5.x anteriores a 4.5.32, 4.7.x anteriores a 4.7.17, 6.0.x anteriores a 6.0.12, 6.1.x anteriores a 6.1.7, y las... • http://osvdb.org/100881 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2013-7076 – Debian Security Advisory 2834-1
https://notcve.org/view.php?id=CVE-2013-7076
21 Dec 2013 — Cross-site scripting (XSS) vulnerability in Extension Manager in TYPO3 4.5.x before 4.5.32 and 4.7.x before 4.7.17 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad cross-site scripting (XSS) en Extension Manager de TYPO3 4.5.x anteriores a 4.5.32 y 4.7.x anteriores a 4.7.17 permite a atacantes remotos inyectar script web o HTML de forma arbitraria a través de vectores no especificados. Several vulnerabilities were discovered in TYPO3, a content managemen... • http://osvdb.org/100883 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2012-6144
https://notcve.org/view.php?id=CVE-2012-6144
01 Jul 2013 — SQL injection vulnerability in the Backend History module in TYPO3 4.5.x before 4.5.21, 4.6.x before 4.6.14, and 4.7.x before 4.7.6 allows remote authenticated backend users to execute arbitrary SQL commands via unspecified vectors. Vulnerabilidad de inyección SQL en el módulo BackEnd History en TYPO3 4.5.x anterior a 4.5.21, 4.6.x anterior a 4.6.14, y 4.7.x anterior a 4.7.6, permite a usuarios del backend autenticados remotamente inyectar comandos SQL arbitrarios a través de vectores no especificados. • http://osvdb.org/87115 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2012-6147
https://notcve.org/view.php?id=CVE-2012-6147
01 Jul 2013 — Cross-site scripting (XSS) vulnerability in the tree render API (TCA-Tree) in the Backend API in TYPO3 4.5.x before 4.5.21, 4.6.x before 4.6.14, and 4.7.x before 4.7.6 allows remote authenticated backend users to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad Cross-site scripting (XSS) en el árbol "render API" (TCA-Tree) en el "Backend API" en TYPO3 v4.5.x anterior a v4.5.21, v4.6.x anterior a v4.6.14, y v4.7.x anterior a v4.7.6 permite a usuarios remotos autenticados inyectar s... • http://osvdb.org/87113 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2012-6148
https://notcve.org/view.php?id=CVE-2012-6148
01 Jul 2013 — Cross-site scripting (XSS) vulnerability in the function menu API in TYPO3 4.5.x before 4.5.21, 4.6.x before 4.6.14, and 4.7.x before 4.7.6 allows remote authenticated backend users to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad XSS en la función menu API en TYPO3 4.5.x anterior a 4.5.21, 4.6.x anterior a 4.6.14, y 4.7.x anterior a 4.7.6, permite a usuarios del backend autenticados remotamente inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no espe... • http://osvdb.org/87114 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2012-6145
https://notcve.org/view.php?id=CVE-2012-6145
01 Jul 2013 — Cross-site scripting (XSS) vulnerability in the Backend History module in TYPO3 4.5.x before 4.5.21, 4.6.x before 4.6.14, and 4.7.x before 4.7.6 allows remote authenticated backend users to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad XSS en el módulo BackEnd History en TYPO3 4.5.x anterior a 4.5.21, 4.6.x anterior a 4.6.14, y 4.7.x anterior a 4.7.6, permite a usuarios del backend autenticados remotamente inyectar secuencias de comandos web o HTML arbitrarios a través de vecto... • http://osvdb.org/87116 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2013-1843
https://notcve.org/view.php?id=CVE-2013-1843
20 Mar 2013 — Open redirect vulnerability in the Access tracking mechanism in TYPO3 4.5.x before 4.5.24, 4.6.x before 4.6.17, 4.7.x before 4.7.9, and 6.0.x before 6.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. Vulnerabilidad de redirección abierta en el mecanismo de Access tracking en TYPO3 en v4.5.x anterior a v4.5.24, v4.6.x anterior a v4.6.17, v4.7.x anterior a v4.7.9, y v6.0.x anterior a v6.0.3, permite a atacantes remotos redireccionar a s... • http://lists.opensuse.org/opensuse-updates/2013-03/msg00079.html • CWE-399: Resource Management Errors •

CVE-2013-1842
https://notcve.org/view.php?id=CVE-2013-1842
20 Mar 2013 — SQL injection vulnerability in the Extbase Framework in TYPO3 4.5.x before 4.5.24, 4.6.x before 4.6.17, 4.7.x before 4.7.9, and 6.0.x before 6.0.3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to "the Query Object Model and relation values." Vulnerabilidad de inyección SQL en Extbase Framework en TYPO3 v4.5.x anterior a v4.5.24, v4.6.x anterior a v4.6.17, v4.7.x anterior a v4.7.9, y v6.0.x anterior a v6.0.3 permite a atacantes remotos ejecutar comandos SQL a trav... • http://lists.opensuse.org/opensuse-updates/2013-03/msg00079.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •