CVE-2007-6381

SQL injection vulnerability in the indexed_search system extension in TYPO3 3.x, 4.0 through 4.0.7, and 4.1 through 4.1.3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:3.0:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:3.7.0:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:3.7.1:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:3.8:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:3.8.1:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:4.0:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:4.0.4:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:4.0.5:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:4.0.6:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:4.0.7:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:4.1:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:4.1.1:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:4.1.2:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:4.1.3:*:*:*:*:*:*:*

History

21 Nov 2024, 00:40

Type Values Removed Values Added
References () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=457446 - () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=457446 -
References () http://osvdb.org/39506 - () http://osvdb.org/39506 -
References () http://secunia.com/advisories/27969 - () http://secunia.com/advisories/27969 -
References () http://secunia.com/advisories/28243 - () http://secunia.com/advisories/28243 -
References () http://securitytracker.com/id?1019146 - () http://securitytracker.com/id?1019146 -
References () http://typo3.org/teams/security/security-bulletins/typo3-20071210-1/ - Patch () http://typo3.org/teams/security/security-bulletins/typo3-20071210-1/ - Patch
References () http://www.debian.org/security/2007/dsa-1439 - () http://www.debian.org/security/2007/dsa-1439 -
References () http://www.securityfocus.com/bid/26871 - () http://www.securityfocus.com/bid/26871 -
References () http://www.vupen.com/english/advisories/2007/4205 - () http://www.vupen.com/english/advisories/2007/4205 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/39017 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/39017 -

Information

Published : 2007-12-15 02:46

Updated : 2024-11-21 00:40


NVD link : CVE-2007-6381

Mitre link : CVE-2007-6381

CVE.ORG link : CVE-2007-6381


JSON object : View

Products Affected

typo3

  • typo3
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')