
CVE-2013-7073 – Debian Security Advisory 2834-1
https://notcve.org/view.php?id=CVE-2013-7073
23 Dec 2013 — The Content Editing Wizards component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 does not check permissions, which allows remote authenticated editors to read arbitrary TYPO3 table columns via unspecified parameters. El componente Content Editing Wizards para TYPO3 v4.5.0 hasta v4.5.31, v4.7.0 hasta v4.7.16, v6.0.0 hasta v6.0.11, y v6.1.0 hasta v6.1.6 no comprueba los permisos, lo que permite a los editores remotos autenticados leer columnas de tablas ... • http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00028.html • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2013-7075 – Debian Security Advisory 2834-1
https://notcve.org/view.php?id=CVE-2013-7075
23 Dec 2013 — The Content Editing Wizards component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 allows remote authenticated backend users to unserialize arbitrary PHP objects, delete arbitrary files, and possibly have other unspecified impacts via an unspecified parameter, related to a "missing signature." El componente Content Editing Wizards para TYPO3 v4.5.0 hasta v4.5.31, v4.7.0 hasta v4.7.16, v6.0.0 hasta v6.0.11, y v6.1.0 hasta v6.1.6 permite a usuarios del bac... • http://seclists.org/oss-sec/2013/q4/473 • CWE-310: Cryptographic Issues •

CVE-2013-7074 – Debian Security Advisory 2834-1
https://notcve.org/view.php?id=CVE-2013-7074
21 Dec 2013 — Multiple cross-site scripting (XSS) vulnerabilities in Content Editing Wizards in TYPO3 4.5.x before 4.5.32, 4.7.x before 4.7.17, 6.0.x before 6.0.12, 6.1.x before 6.1.7, and the development versions of 6.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters. Múltiples vulnerabilidades de cross-site scripting (XSS) en Content Editing Wizards en TYPO3 4.5.x anteriores a 4.5.32, 4.7.x anteriores a 4.7.17, 6.0.x anteriores a 6.0.12, 6.1.x anteriores a 6.1.7, y las... • http://osvdb.org/100881 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2013-7077
https://notcve.org/view.php?id=CVE-2013-7077
21 Dec 2013 — Cross-site scripting (XSS) vulnerability in the Backend User Administration Module in TYPO3 6.0.x before 6.0.12 and 6.1.x before 6.1.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad cross-site scripting (XSS) en Backend User Administration Module de TYPO3 6.0.x anteriores a 6.0.12 y 6.1.x anteriores a 6.1.7 permite a atacantes remotos inyectar script web o HTML de forma arbitraria a través de vectores no especificados. • http://osvdb.org/100884 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •