|
304351
|
5.3 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness in the uniqid function.
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2010-3666
|
2024-11-21 10:19 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304352
|
5.4 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the Extension Manager.
|
CWE-79
Cross-site Scripting
|
CVE-2010-3665
|
2024-11-21 10:19 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304353
|
6.5 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Information Disclosure on the backend.
|
CWE-200
Information Exposure
|
CVE-2010-3664
|
2024-11-21 10:19 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304354
|
8.8 |
HIGH
Network
|
typo3
|
typo3
|
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains an insecure default value of the variable fileDenyPattern which could allow remote attackers to execute ar…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2010-3663
|
2024-11-21 10:19 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304355
|
8.8 |
HIGH
Network
|
typo3
|
typo3
|
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows SQL Injection on the backend.
|
CWE-89
SQL Injection
|
CVE-2010-3662
|
2024-11-21 10:19 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304356
|
6.1 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Open Redirection on the backend.
|
CWE-601
Open Redirect
|
CVE-2010-3661
|
2024-11-21 10:19 |
2019-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304357
|
5.4 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the backend.
|
CWE-79
Cross-site Scripting
|
CVE-2010-3660
|
2024-11-21 10:19 |
2019-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304358
|
5.4 |
MEDIUM
Network
|
typo3
|
typo3
|
Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 CMS 4.1.x before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4, and 4.4.x before 4.4.1 allow remote authenticated backend users to injec…
|
CWE-79
Cross-site Scripting
|
CVE-2010-3659
|
2024-11-21 10:19 |
2017-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304359
|
9.8 |
CRITICAL
Network
|
apache_authenhook_project
|
apache_authenhook
|
libapache-authenhook-perl 2.00-04 stores usernames and passwords in plaintext in the vhost error log.
|
CWE-200
Information Exposure
|
CVE-2010-3845
|
2024-11-21 10:19 |
2017-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304360
|
- |
|
ffmpeg mplayerhq
|
ffmpeg mplayer
|
FFmpeg before 0.5.4, as used in MPlayer and other products, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a mal…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-3908
|
2024-11-21 10:19 |
2011-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|