CVE-2012-2112
Debian Security Advisory 2455-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in the Exception Handler in TYPO3 4.4.x before 4.4.15, 4.5.x before 4.5.15, 4.6.x before 4.6.8, and 4.7 allows remote attackers to inject arbitrary web script or HTML via exception messages.
Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en el controlador de excepciones en TYPO3 v4.4.x anterior a v4.4.15, v4.5.15 anterior a v4.5.x, v4.6.x anterior a v4.6.8, y v4.7, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de mensajes de excepción.
Helmut Hummel of the typo3 security team discovered that typo3, a web content management system, is not properly sanitizing output of the exception handler. This allows an attacker to conduct cross-site scripting attacks if either third-party extensions are installed that do not sanitize this output on their own or in the presence of extensions using the extbase MVC framework which accept objects to controller actions.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-04-04 CVE Reserved
- 2012-04-20 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://lists.typo3.org/pipermail/typo3-announce/2012/000241.html | Mailing List | |
http://lists.typo3.org/pipermail/typo3-announce/2012/000242.html | Mailing List | |
http://www.openwall.com/lists/oss-security/2012/04/17/5 | Mailing List |
|
http://www.openwall.com/lists/oss-security/2012/04/18/1 | Mailing List |
|
http://www.securityfocus.com/bid/53047 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/74920 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2012-002 | 2017-08-29 | |
http://www.debian.org/security/2012/dsa-2455 | 2017-08-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.4.0 Search vendor "Typo3" for product "Typo3" and version "4.4.0" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.4.1 Search vendor "Typo3" for product "Typo3" and version "4.4.1" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.4.2 Search vendor "Typo3" for product "Typo3" and version "4.4.2" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.4.3 Search vendor "Typo3" for product "Typo3" and version "4.4.3" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.4.4 Search vendor "Typo3" for product "Typo3" and version "4.4.4" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.4.5 Search vendor "Typo3" for product "Typo3" and version "4.4.5" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.4.6 Search vendor "Typo3" for product "Typo3" and version "4.4.6" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.4.7 Search vendor "Typo3" for product "Typo3" and version "4.4.7" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.4.8 Search vendor "Typo3" for product "Typo3" and version "4.4.8" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.4.9 Search vendor "Typo3" for product "Typo3" and version "4.4.9" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.4.10 Search vendor "Typo3" for product "Typo3" and version "4.4.10" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.4.11 Search vendor "Typo3" for product "Typo3" and version "4.4.11" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.4.12 Search vendor "Typo3" for product "Typo3" and version "4.4.12" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.4.13 Search vendor "Typo3" for product "Typo3" and version "4.4.13" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.4.14 Search vendor "Typo3" for product "Typo3" and version "4.4.14" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.5.0 Search vendor "Typo3" for product "Typo3" and version "4.5.0" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.5.1 Search vendor "Typo3" for product "Typo3" and version "4.5.1" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.5.2 Search vendor "Typo3" for product "Typo3" and version "4.5.2" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.5.3 Search vendor "Typo3" for product "Typo3" and version "4.5.3" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.5.4 Search vendor "Typo3" for product "Typo3" and version "4.5.4" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.5.5 Search vendor "Typo3" for product "Typo3" and version "4.5.5" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.5.6 Search vendor "Typo3" for product "Typo3" and version "4.5.6" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.5.7 Search vendor "Typo3" for product "Typo3" and version "4.5.7" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.5.8 Search vendor "Typo3" for product "Typo3" and version "4.5.8" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.5.9 Search vendor "Typo3" for product "Typo3" and version "4.5.9" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.5.10 Search vendor "Typo3" for product "Typo3" and version "4.5.10" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.5.11 Search vendor "Typo3" for product "Typo3" and version "4.5.11" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.5.12 Search vendor "Typo3" for product "Typo3" and version "4.5.12" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.5.13 Search vendor "Typo3" for product "Typo3" and version "4.5.13" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.5.14 Search vendor "Typo3" for product "Typo3" and version "4.5.14" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.6.0 Search vendor "Typo3" for product "Typo3" and version "4.6.0" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.6.1 Search vendor "Typo3" for product "Typo3" and version "4.6.1" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.6.2 Search vendor "Typo3" for product "Typo3" and version "4.6.2" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.6.3 Search vendor "Typo3" for product "Typo3" and version "4.6.3" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.6.4 Search vendor "Typo3" for product "Typo3" and version "4.6.4" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.6.5 Search vendor "Typo3" for product "Typo3" and version "4.6.5" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.6.6 Search vendor "Typo3" for product "Typo3" and version "4.6.6" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.6.7 Search vendor "Typo3" for product "Typo3" and version "4.6.7" | - |
Affected
| ||||||
Typo3 Search vendor "Typo3" | Typo3 Search vendor "Typo3" for product "Typo3" | 4.7 Search vendor "Typo3" for product "Typo3" and version "4.7" | - |
Affected
|