Page 4 of 28 results (0.004 seconds)

CVSS: 6.5EPSS: 0%CPEs: 68EXPL: 0

The Content Editing Wizards component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 allows remote authenticated backend users to unserialize arbitrary PHP objects, delete arbitrary files, and possibly have other unspecified impacts via an unspecified parameter, related to a "missing signature." El componente Content Editing Wizards para TYPO3 v4.5.0 hasta v4.5.31, v4.7.0 hasta v4.7.16, v6.0.0 hasta v6.0.11, y v6.1.0 hasta v6.1.6 permite a usuarios del backend autenticados desserializar objetos PHP, eliminar cualquier fichero, y posiblemente tener otros impactos no especificados a través de un parámetro sin especificar, relacionado con una "falta de firma". • http://seclists.org/oss-sec/2013/q4/473 http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2013-004 http://www.debian.org/security/2014/dsa-2834 • CWE-310: Cryptographic Issues •

CVSS: 5.8EPSS: 0%CPEs: 68EXPL: 0

Open redirect vulnerability in the OpenID extension in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. Vulnerabilidad de redirección abierta en la extensión de OpenID en TYPO3 4.5.0 a 4.5.31, 4.7.0 a 4.7.16, 6.0.0 a 6.0.11, y 6.1.0 a 6.1.6 permite a atacantes remotos redireccionar usuarios a sitios web arbitrarios y efectuar ataques de phishing a través de vectores no especificados. • http://seclists.org/oss-sec/2013/q4/473 http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2013-004 http://www.debian.org/security/2014/dsa-2834 http://www.securityfocus.com/bid/64252 • CWE-20: Improper Input Validation •

CVSS: 5.8EPSS: 0%CPEs: 61EXPL: 0

The creating record functionality in Extension table administration library (feuser_adminLib.inc) in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, and 6.0.0 through 6.0.11 allows remote attackers to write to arbitrary fields in the configuration database table via crafted links, aka "Mass Assignment." La funcionalidad de creación de registros en la tabla de administración de la librería (feuser_adminLib.inc) Extension en TYPO3 4.5.0 a 4.5.31, 4.7.0 a 4.7.16, y 6.0.0 a 6.0.11 permite a atacantes remotos escribir en campos arbitrarios en la tabla de configuración de la base de datos a través de enlaces manipulados, también conocido como "Mass Assignment" (asignación masiva). • http://seclists.org/oss-sec/2013/q4/473 http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2013-004 http://www.debian.org/security/2014/dsa-2834 •

CVSS: 4.9EPSS: 0%CPEs: 68EXPL: 0

The (old) Form Content Element component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 allows remote authenticated editors to generate arbitrary HMAC signatures and bypass intended access restrictions via unspecified vectors. El (antiguo) componente Form Content Element en TYPO3 4.5.0 a 4.5.31, 4.7.0 a 4.7.16, 6.0.0 a 6.0.11, y 6.1.0 a 6.1.6 permite a editores autenticados remotamente generar firmas HMAC arbitrarias y sortear restricciones de acceso intencionadas a través de vectores no especificados. • http://seclists.org/oss-sec/2013/q4/473 http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2013-004 http://www.debian.org/security/2014/dsa-2834 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 3.5EPSS: 0%CPEs: 71EXPL: 0

Multiple cross-site scripting (XSS) vulnerabilities in Content Editing Wizards in TYPO3 4.5.x before 4.5.32, 4.7.x before 4.7.17, 6.0.x before 6.0.12, 6.1.x before 6.1.7, and the development versions of 6.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters. Múltiples vulnerabilidades de cross-site scripting (XSS) en Content Editing Wizards en TYPO3 4.5.x anteriores a 4.5.32, 4.7.x anteriores a 4.7.17, 6.0.x anteriores a 6.0.12, 6.1.x anteriores a 6.1.7, y las versiones de desarrollo 6.2, permite a usuarios autenticados remotamente inyectar scripts web o HTML arbitrarios a través de parámetros no especificados. • http://osvdb.org/100881 http://seclists.org/oss-sec/2013/q4/473 http://seclists.org/oss-sec/2013/q4/487 http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2013-004 http://www.debian.org/security/2014/dsa-2834 http://www.securityfocus.com/bid/64245 https://exchange.xforce.ibmcloud.com/vulnerabilities/89620 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •