CVE-2012-1071
https://notcve.org/view.php?id=CVE-2012-1071
SQL injection vulnerability in the Kitchen recipe (mv_cooking) extension before 0.4.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, as exploited in the wild as of February 2012. Vulnerabilidad de inyección de comandos SQL en la extensión Kitchen recipe (mv_cooking) v0.4.1 para TYPO3, permite a atacantes remotos ejecutar comandos SQL de su elección a través de vectores no especificados, como se explotó a partir de Febrero de 2012. • http://osvdb.org/78748 http://secunia.com/advisories/47437 http://typo3.org/extensions/repository/view/mv_cooking/0.4.1 http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2012-001 http://www.securityfocus.com/bid/51825 https://exchange.xforce.ibmcloud.com/vulnerabilities/72934 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2012-1078
https://notcve.org/view.php?id=CVE-2012-1078
The System Utilities (sysutils) extension 1.0.3 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unspecified vectors related to improper "protection" of the "backup output directory." La extensión System Utilities (sysutils) v1.0.3 y anteriores para TYPO3, permite a atacantes remotos obtener información sensible a través de vectores no especificados relacionados con la "protección" impropia del "directorio de salida de copia de seguridad" • http://typo3.org/extensions/repository/view/sysutils/1.0.4 http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2012-001 http://www.osvdb.org/78791 http://www.securityfocus.com/bid/51844 https://exchange.xforce.ibmcloud.com/vulnerabilities/72964 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2012-1077
https://notcve.org/view.php?id=CVE-2012-1077
SQL injection vulnerability in the Post data records to facebook (bc_post2facebook) extension before 0.2.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. Vulnerabilidad de inyección de comandos SQL en la extensión Post data records to facebook (bc_post2facebook) v0.2.2 para TYPO3, permite a atacantes remotos ejecutar comandos SQL de su elección a través de vectores no especificados. • http://osvdb.org/78790 http://typo3.org/extensions/repository/view/bc_post2facebook/0.2.2 http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2012-001 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2012-1083
https://notcve.org/view.php?id=CVE-2012-1083
Cross-site request forgery (CSRF) vulnerability in the Terminal PHP Shell (terminal) extension 0.3.2 and earlier for TYPO3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en la extensión Terminal PHP Shell (terminal) v0.3.2 y anteriores para TYPO3, permite a atacantes remotos secuestrar la autenticación de victimas no especificadas a través de vectores desconocidos. • http://osvdb.org/78797 http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2012-001 http://www.securityfocus.com/bid/51849 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2011-5080
https://notcve.org/view.php?id=CVE-2011-5080
Cross-site scripting (XSS) vulnerability in lib/class.tx_jftcaforms_tceFunc.php in the Additional TCA Forms (jftcaforms) extension before 0.2.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en lib/class.tx_jftcaforms_tceFunc.php en la extensión Additional TCA Forms (jftcaforms) v0.2.1 para TYPO3, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de vectores no especificados. • http://forge.typo3.org/projects/extension-jftcaforms/repository/diff?rev=51637&rev_to=51568 http://osvdb.org/78800 http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2012-001 http://www.securityfocus.com/bid/51854 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •