CVE-2009-3632
 
Severity Score
6.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
SQL injection vulnerability in the traditional frontend editing feature in the Frontend Editing subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote authenticated users to execute arbitrary SQL commands via unspecified parameters.
Vulnerabilidad de inyección SQL en la funcionalidad de edición del "frontend" (portal de usuario) tradicional del subcomponente "Frontend Editing" (edición del portal de usuario) de TYPO3 v4.0.13 y anteriores, v4.1.x anteriores a v4.1.13, v4.2.x anteriores a v4.2.10 y v4.3.x anteriores a v4.3beta2. Permite a usuarios remotos ejecutar comandos SQL de su elección a través parámetros sin especificar.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2009-10-09 CVE Reserved
- 2009-11-02 CVE Published
- 2024-08-07 CVE Updated
- 2024-10-09 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://marc.info/?l=oss-security&m=125632856206736&w=2 | Mailing List | |
http://www.securityfocus.com/bid/36801 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/53924 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.vupen.com/english/advisories/2009/3009 | 2017-08-17 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/37122 | 2017-08-17 | |
http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-016 | 2017-08-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | <= 4.0.13 Search vendor "Typo3" for product "Typo3" and version " <= 4.0.13" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.0 Search vendor "Typo3" for product "Typo3" and version "4.0" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.0.1 Search vendor "Typo3" for product "Typo3" and version "4.0.1" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.0.2 Search vendor "Typo3" for product "Typo3" and version "4.0.2" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.0.3 Search vendor "Typo3" for product "Typo3" and version "4.0.3" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.0.4 Search vendor "Typo3" for product "Typo3" and version "4.0.4" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.0.5 Search vendor "Typo3" for product "Typo3" and version "4.0.5" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.0.6 Search vendor "Typo3" for product "Typo3" and version "4.0.6" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.0.7 Search vendor "Typo3" for product "Typo3" and version "4.0.7" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.0.8 Search vendor "Typo3" for product "Typo3" and version "4.0.8" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.0.9 Search vendor "Typo3" for product "Typo3" and version "4.0.9" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.0.10 Search vendor "Typo3" for product "Typo3" and version "4.0.10" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.0.11 Search vendor "Typo3" for product "Typo3" and version "4.0.11" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.0.12 Search vendor "Typo3" for product "Typo3" and version "4.0.12" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.1 Search vendor "Typo3" for product "Typo3" and version "4.1" | beta |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.1 Search vendor "Typo3" for product "Typo3" and version "4.1" | rc1 |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.1.0 Search vendor "Typo3" for product "Typo3" and version "4.1.0" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.1.0 Search vendor "Typo3" for product "Typo3" and version "4.1.0" | beta1 |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.1.0 Search vendor "Typo3" for product "Typo3" and version "4.1.0" | rc1 |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.1.1 Search vendor "Typo3" for product "Typo3" and version "4.1.1" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.1.2 Search vendor "Typo3" for product "Typo3" and version "4.1.2" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.1.3 Search vendor "Typo3" for product "Typo3" and version "4.1.3" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.1.4 Search vendor "Typo3" for product "Typo3" and version "4.1.4" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.1.5 Search vendor "Typo3" for product "Typo3" and version "4.1.5" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.1.6 Search vendor "Typo3" for product "Typo3" and version "4.1.6" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.1.7 Search vendor "Typo3" for product "Typo3" and version "4.1.7" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.1.8 Search vendor "Typo3" for product "Typo3" and version "4.1.8" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.1.9 Search vendor "Typo3" for product "Typo3" and version "4.1.9" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.1.10 Search vendor "Typo3" for product "Typo3" and version "4.1.10" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.1.11 Search vendor "Typo3" for product "Typo3" and version "4.1.11" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.1.12 Search vendor "Typo3" for product "Typo3" and version "4.1.12" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.2.0 Search vendor "Typo3" for product "Typo3" and version "4.2.0" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.2.1 Search vendor "Typo3" for product "Typo3" and version "4.2.1" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.2.2 Search vendor "Typo3" for product "Typo3" and version "4.2.2" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.2.3 Search vendor "Typo3" for product "Typo3" and version "4.2.3" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.2.4 Search vendor "Typo3" for product "Typo3" and version "4.2.4" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.2.5 Search vendor "Typo3" for product "Typo3" and version "4.2.5" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.2.6 Search vendor "Typo3" for product "Typo3" and version "4.2.6" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.2.7 Search vendor "Typo3" for product "Typo3" and version "4.2.7" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.2.8 Search vendor "Typo3" for product "Typo3" and version "4.2.8" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.2.9 Search vendor "Typo3" for product "Typo3" and version "4.2.9" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.3 Search vendor "Typo3" for product "Typo3" and version "4.3" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.3 Search vendor "Typo3" for product "Typo3" and version "4.3" | alpha1 |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.3 Search vendor "Typo3" for product "Typo3" and version "4.3" | beta1 |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.10 Search vendor "Typo3" for product "Typo3" and version "4.10" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.11 Search vendor "Typo3" for product "Typo3" and version "4.11" | - |
Affected
|