CVE-2010-0332
https://notcve.org/view.php?id=CVE-2010-0332
SQL injection vulnerability in the TV21 Talkshow (tv21_talkshow) extension 1.0.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. Vulnerabilidad de inyección SQL en la extensión de TYPO3 "Talkshow TV21"(tv21_talkshow) v1.0.1 y anteriores permite a atacantes remotos ejecutar comandos SQL a través de vectores no especificados. • http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2010-0344
https://notcve.org/view.php?id=CVE-2010-0344
SQL injection vulnerability in the zak_store_management extension 1.0.0 and earlier TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. Vulnerabilidad de inyección SQL en la extensión de TYPO3 "zak_store_management" v1.0.0 y anteriores permite a atacantes remotos ejecutar comandos SQL a través de vectores no especificados • http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2010-0346
https://notcve.org/view.php?id=CVE-2010-0346
Cross-site scripting (XSS) vulnerability in the Tip many friends (mimi_tipfriends) extension 0.0.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de ejecución de comandos en sitios cruzados(XSS) en la extensión de TYPO3 "Tip many friends"(mimi_tipfriends) v0.0.2 y anteriores permite a atacantes remotos inyectar HTML o scripts web a través de vectores no especificados. • http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2010-0322
https://notcve.org/view.php?id=CVE-2010-0322
SQL injection vulnerability in the init function in MK-AnydropdownMenu (mk_anydropdownmenu) extension 0.3.28 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. Vulnerabilidad de inyección SQL en la función init de la extensión de TYPO3 "MK-AnydropdownMenu" v0.3.28 y anteriores permite a atacantes remotos ejecutar comandos SQL a través de vectores no especificados. • http://typo3.org/extensions/repository/view/mk_anydropdownmenu/0.4.0 http://typo3.org/extensions/repository/view/mk_anydropdownmenu/0.4.0/info/ChangeLog http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2010-0330
https://notcve.org/view.php?id=CVE-2010-0330
SQL injection vulnerability in the Googlemaps for tt_news (jf_easymaps) extension 1.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. Vulnerabilidad de inyección SQL en el en la extensión de TYPO3 "Googlemaps para tt_news" (jf_easymaps) v1.0.2 y anteriores permite a atacantes remotos ejecutar comandos SQL a través de vectores no especificados. • http://typo3.org/extensions/repository/view/jf_easymaps/1.0.3 http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •