|
301021
|
6.5 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 is open to a session fixation attack which allows remote attackers to hijack a victim's session.
|
CWE-384
Session Fixation
|
CVE-2010-3671
|
2024-11-21 10:19 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
301022
|
4.8 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness during generation of a hash with the "forgot password" function.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2010-3670
|
2024-11-21 10:19 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
301023
|
5.4 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS and Open Redirection in the frontend login box.
|
CWE-79 CWE-601
Cross-site Scripting Open Redirect
|
CVE-2010-3669
|
2024-11-21 10:19 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
301024
|
7.5 |
HIGH
Network
|
typo3
|
typo3
|
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Header Injection in the secure download feature jumpurl.
|
CWE-74
Injection
|
CVE-2010-3668
|
2024-11-21 10:19 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
301025
|
5.3 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Spam Abuse in the native form content element.
|
CWE-20
Improper Input Validation
|
CVE-2010-3667
|
2024-11-21 10:19 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
301026
|
5.3 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness in the uniqid function.
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2010-3666
|
2024-11-21 10:19 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
301027
|
5.4 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the Extension Manager.
|
CWE-79
Cross-site Scripting
|
CVE-2010-3665
|
2024-11-21 10:19 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
301028
|
6.5 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Information Disclosure on the backend.
|
CWE-200
Information Exposure
|
CVE-2010-3664
|
2024-11-21 10:19 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
301029
|
8.8 |
HIGH
Network
|
typo3
|
typo3
|
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains an insecure default value of the variable fileDenyPattern which could allow remote attackers to execute ar…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2010-3663
|
2024-11-21 10:19 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
301030
|
8.8 |
HIGH
Network
|
typo3
|
typo3
|
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows SQL Injection on the backend.
|
CWE-89
SQL Injection
|
CVE-2010-3662
|
2024-11-21 10:19 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|