| Title | TYPO3 の Content Editing Wizards コンポーネントにおける任意の TYPO3 テーブルの列を読まれる脆弱性 |
|---|---|
| Summary | TYPO3 の Content Editing Wizards コンポーネントは、権限をチェックしないため、任意の TYPO3 テーブルの列を読まれる脆弱性が存在します。 |
| Possible impacts | リモート認証された編集者により、不特定のパラメータを介して、任意の TYPO3 テーブルの列を読まれる可能性があります。 |
| Solution | ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date | Dec. 10, 2013, midnight |
| Registration Date | Dec. 25, 2013, 5:30 p.m. |
| Last Update | Dec. 25, 2013, 5:30 p.m. |
| CVSS2.0 : 警告 | |
| Score | 4 |
|---|---|
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:N |
| TYPO3 Association |
| TYPO3 4.5.0 から 4.5.31 |
| TYPO3 4.7.0 から 4.7.16 |
| TYPO3 6.0.0 から 6.0.11 |
| TYPO3 6.1.0 から 6.1.6 |
| No | Changed Details | Date of change |
|---|---|---|
| 0 | [2013年12月25日] 掲載 |
Feb. 17, 2018, 10:37 a.m. |
| Summary | The Content Editing Wizards component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 does not check permissions, which allows remote authenticated editors to read arbitrary TYPO3 table columns via unspecified parameters. |
|---|---|
| Publication Date | Dec. 24, 2013, 8:55 a.m. |
| Registration Date | Jan. 26, 2021, 3:49 p.m. |
| Last Update | Nov. 21, 2024, 11 a.m. |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:a:typo3:typo3:4.5.30:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.5.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.5.27:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.5.9:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.5.12:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.5.24:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.5.15:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.5.5:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.5.13:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.5.17:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.5.8:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.5.14:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.5.23:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.5.7:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.5.20:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.5.6:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.5.18:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.5.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.5.26:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.5.29:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.5.21:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.5.31:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.5.11:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.5.19:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.5.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.5.16:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.5.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.5.25:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.5.22:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.5.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.5.10:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.5.28:*:*:*:*:*:*:* | |||||
| Configuration2 | or higher | or less | more than | less than | |
| cpe:2.3:a:typo3:typo3:6.1.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:6.1.6:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:6.1.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:6.1.5:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:6.1.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:6.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:6.1.2:*:*:*:*:*:*:* | |||||
| Configuration3 | or higher | or less | more than | less than | |
| cpe:2.3:a:typo3:typo3:6.0.11:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:6.0.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:6.0.10:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:6.0.8:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:6.0.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:6.0.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:6.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:6.0.9:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:6.0.6:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:6.0.5:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:6.0.7:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:6.0.4:*:*:*:*:*:*:* | |||||
| Configuration4 | or higher | or less | more than | less than | |
| cpe:2.3:a:typo3:typo3:4.7.5:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.7.8:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.7.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.7.13:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.7.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.7.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.7.12:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.7.7:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.7.10:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.7.14:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.7.11:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.7.15:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.7.6:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.7.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.7.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.7.16:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:typo3:typo3:4.7.9:*:*:*:*:*:*:* | |||||