|
294521
|
5.4 |
MEDIUM
Network
|
typo3
|
typo3
|
Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the tcemain flash message.
|
CWE-79
Cross-site Scripting
|
CVE-2011-4632
|
2024-11-21 10:32 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294522
|
5.4 |
MEDIUM
Network
|
typo3
|
typo3
|
Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the system extension recycler.
|
CWE-79
Cross-site Scripting
|
CVE-2011-4631
|
2024-11-21 10:32 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294523
|
5.4 |
MEDIUM
Network
|
typo3
|
typo3
|
Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the browse_links wizard.
|
CWE-79
Cross-site Scripting
|
CVE-2011-4630
|
2024-11-21 10:32 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294524
|
5.4 |
MEDIUM
Network
|
typo3
|
typo3
|
Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the admin panel.
|
CWE-79
Cross-site Scripting
|
CVE-2011-4629
|
2024-11-21 10:32 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294525
|
9.8 |
CRITICAL
Network
|
typo3
|
typo3
|
TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to bypass authentication mechanisms in the backend through a crafted request.
|
CWE-287
Improper Authentication
|
CVE-2011-4628
|
2024-11-21 10:32 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294526
|
6.5 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows Information Disclosure on the backend.
|
CWE-200
Information Exposure
|
CVE-2011-4627
|
2024-11-21 10:32 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294527
|
6.1 |
MEDIUM
Network
|
typo3
|
typo3
|
Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the "JSwindow" property of the typolin…
|
CWE-79
Cross-site Scripting
|
CVE-2011-4626
|
2024-11-21 10:32 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294528
|
7.5 |
HIGH
Network
|
simplesamlphp debian
|
simplesamlphp debian_linux
|
simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt or forge messages.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2011-4625
|
2024-11-21 10:32 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294529
|
8.8 |
HIGH
Network
|
labwiki_project
|
labwiki
|
edit.php in LabWiki 1.1 and earlier does not properly verify uploaded user files, which allows remote authenticated users to upload arbitrary PHP files via a PHP file with a .gif extension in the use…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2011-4334
|
2024-11-21 10:32 |
2017-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294530
|
6.1 |
MEDIUM
Network
|
scilico
|
labwiki
|
Multiple cross-site scripting (XSS) vulnerabilities in LabWiki 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) from parameter to index.php or the (2) page_no…
|
CWE-79
Cross-site Scripting
|
CVE-2011-4333
|
2024-11-21 10:32 |
2017-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|