This CPE summary could be partial or incomplete. Please contact us for a detailed listing.
Summary
| Summuary | |
|---|---|
| CPE Name | cpe:/a:typo3:typo3:4.3:alpha1 |
| Detail | |||
|---|---|---|---|
| Vendor | typo3 | First view | 2009-03-04 |
| Product | typo3 | Last view | 2009-11-02 |
| Version | 4.3 | Type | Application |
| Edition | |||
| Language | |||
| Update | alpha1 | ||
| CPE Product | cpe:/a:typo3:typo3 | ||
Activity : Yearly
Related : CVE
| Date | Alert | Access Vector | Access Complexity | Authentification | ||
|---|---|---|---|---|---|---|
| 4.3 | 2009-11-02 | CVE-2009-3636 | Network | Medium | None Requ... | |
| 6.8 | 2009-11-02 | CVE-2009-3635 | Network | Medium | None Requ... | |
| 4.3 | 2009-11-02 | CVE-2009-3633 | Network | Medium | None Requ... | |
| 6.5 | 2009-11-02 | CVE-2009-3632 | Network | Low | Requires ... | |
| 8.5 | 2009-11-02 | CVE-2009-3631 | Network | Medium | Requires ... | |
| Date | Alert | Access Vector | Access Complexity | Authentification | ||
|---|---|---|---|---|---|---|
| 5.5 | 2009-11-02 | CVE-2009-3630 | Network | Low | Requires ... | |
| 3.5 | 2009-11-02 | CVE-2009-3629 | Network | Medium | Requires ... | |
| 4 | 2009-11-02 | CVE-2009-3628 | Network | Low | Requires ... | |
| 5 | 2009-03-04 | CVE-2009-0815 | Network | Low | None Requ... |
CWE : Common Weakness Enumeration
| % | id | Name |
|---|---|---|
| 25% (2) | CWE-200 | Information Exposure |
| 25% (2) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
| 12% (1) | CWE-352 | Cross-Site Request Forgery (CSRF) |
| 12% (1) | CWE-287 | Improper Authentication |
| 12% (1) | CWE-94 | Failure to Control Generation of Code ('Code Injection') |
| % | id | Name |
|---|---|---|
| 12% (1) | CWE-89 | Improper Sanitization of Special Elements used in an SQL Command ('... |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 59491 | Typo3 Core Install Tool Unspecified URL Parameter XSS |
| 59490 | Typo3 Core Install Tool MD5 Hash Authentication Bypass |
| 59488 | Typo3 Core t3lib_div::quoteJSvalue API Function XSS |
| 59487 | Typo3 Core Frontend Editing Unspecified URL Parameter SQL Injection |
| 59486 | Typo3 Core Backend Crafted File Upload Arbitrary Command Execution |
| id | Description |
|---|---|
| 59485 | Typo3 Core Backend Unspecified Frame Hijacking |
| 59484 | Typo3 Core Backend Multiple Unspecified XSS |
| 59483 | Typo3 Core Backend tt_content Form Element Encryption Key Recalculation |
| 52048 | TYPO3 class.tslib_fe.php 3 jump_url Function Arbitrary File Access |
Metasploit Exploits
| id | Description |
|---|---|
| 2009-02-10 | Typo3 sa-2009-002 File Disclosure |








