Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.804219
Categoría:Web application abuses
Título:TYPO3 Multiple Vulnerabilities Oct10
Resumen:This host is installed with TYPO3 and is prone to multiple vulnerabilities.
Descripción:Summary:
This host is installed with TYPO3 and is prone to multiple vulnerabilities.

Vulnerability Insight:
Multiple errors exist in the application:

- An error exists in class.tslib_fe.php script, which does not properly compare
certain hash values during access-control decisions.

- An error exists backend and sys_action task, which fails to validate certain
user provided input properly.

- An error exists in Filtering API, which fails to handle large strings.

Vulnerability Impact:
Successful exploitation will allow remote attackers to get sensitive
information or cause DoS condition.

Affected Software/OS:
TYPO3 version 4.2.14 and below, 4.3.6 and below, 4.4.3 and below

Solution:
Upgrade to TYPO3 version 4.2.15, 4.3.7, 4.4.4 or later.

CVSS Score:
7.1

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:N/A:N

Referencia Cruzada: BugTraq ID: 43786
Common Vulnerability Exposure (CVE) ID: CVE-2010-3714
http://www.securityfocus.com/bid/43786
Debian Security Information: DSA-2121 (Google Search)
http://www.debian.org/security/2010/dsa-2121
http://www.exploit-db.com/exploits/15856
http://blog.nibblesec.org/2010/12/typo3-sa-2010-020-typo3-sa-2010-022.html
Common Vulnerability Exposure (CVE) ID: CVE-2010-3715
Common Vulnerability Exposure (CVE) ID: CVE-2010-3716
Common Vulnerability Exposure (CVE) ID: CVE-2010-3717
Common Vulnerability Exposure (CVE) ID: CVE-2010-4068
CopyrightCopyright (C) 2014 Greenbone Networks GmbH

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.