
CVE-2013-7079 – Debian Security Advisory 2834-1
https://notcve.org/view.php?id=CVE-2013-7079
23 Dec 2013 — Open redirect vulnerability in the OpenID extension in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. Vulnerabilidad de redirección abierta en la extensión de OpenID en TYPO3 4.5.0 a 4.5.31, 4.7.0 a 4.7.16, 6.0.0 a 6.0.11, y 6.1.0 a 6.1.6 permite a atacantes remotos redireccionar usuarios a sitios web arbitrarios y efectuar ataques de phishin... • http://seclists.org/oss-sec/2013/q4/473 • CWE-20: Improper Input Validation •

CVE-2013-7081 – Debian Security Advisory 2834-1
https://notcve.org/view.php?id=CVE-2013-7081
23 Dec 2013 — The (old) Form Content Element component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 allows remote authenticated editors to generate arbitrary HMAC signatures and bypass intended access restrictions via unspecified vectors. El (antiguo) componente Form Content Element en TYPO3 4.5.0 a 4.5.31, 4.7.0 a 4.7.16, 6.0.0 a 6.0.11, y 6.1.0 a 6.1.6 permite a editores autenticados remotamente generar firmas HMAC arbitrarias y sortear restricciones de acceso inten... • http://seclists.org/oss-sec/2013/q4/473 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2013-7074 – Debian Security Advisory 2834-1
https://notcve.org/view.php?id=CVE-2013-7074
21 Dec 2013 — Multiple cross-site scripting (XSS) vulnerabilities in Content Editing Wizards in TYPO3 4.5.x before 4.5.32, 4.7.x before 4.7.17, 6.0.x before 6.0.12, 6.1.x before 6.1.7, and the development versions of 6.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters. Múltiples vulnerabilidades de cross-site scripting (XSS) en Content Editing Wizards en TYPO3 4.5.x anteriores a 4.5.32, 4.7.x anteriores a 4.7.17, 6.0.x anteriores a 6.0.12, 6.1.x anteriores a 6.1.7, y las... • http://osvdb.org/100881 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2013-7077
https://notcve.org/view.php?id=CVE-2013-7077
21 Dec 2013 — Cross-site scripting (XSS) vulnerability in the Backend User Administration Module in TYPO3 6.0.x before 6.0.12 and 6.1.x before 6.1.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad cross-site scripting (XSS) en Backend User Administration Module de TYPO3 6.0.x anteriores a 6.0.12 y 6.1.x anteriores a 6.1.7 permite a atacantes remotos inyectar script web o HTML de forma arbitraria a través de vectores no especificados. • http://osvdb.org/100884 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •