CVE-2009-1264

Frontend User Registration (sr_feuser_register) extension 2.5.20 and earlier for TYPO3 does not properly verify access rights, which allows remote authenticated users to obtain sensitive information such as passwords via unknown attack vectors.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
OR cpe:2.3:a:stanislas_rolland:sr_feuser_register:*:*:*:*:*:*:*:*
cpe:2.3:a:stanislas_rolland:sr_feuser_register:1.4:*:*:*:*:*:*:*
cpe:2.3:a:stanislas_rolland:sr_feuser_register:1.6:*:*:*:*:*:*:*
cpe:2.3:a:stanislas_rolland:sr_feuser_register:2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:stanislas_rolland:sr_feuser_register:2.2.7:*:*:*:*:*:*:*
cpe:2.3:a:stanislas_rolland:sr_feuser_register:2.2.8:*:*:*:*:*:*:*
cpe:2.3:a:stanislas_rolland:sr_feuser_register:2.3:*:*:*:*:*:*:*
cpe:2.3:a:stanislas_rolland:sr_feuser_register:2.3.6:*:*:*:*:*:*:*
cpe:2.3:a:stanislas_rolland:sr_feuser_register:2.4:*:*:*:*:*:*:*
cpe:2.3:a:stanislas_rolland:sr_feuser_register:2.5:*:*:*:*:*:*:*
cpe:2.3:a:stanislas_rolland:sr_feuser_register:2.5.10:*:*:*:*:*:*:*

History

21 Nov 2024, 01:02

Type Values Removed Values Added
References () http://osvdb.org/53278 - () http://osvdb.org/53278 -
References () http://secunia.com/advisories/34586 - Vendor Advisory () http://secunia.com/advisories/34586 - Vendor Advisory
References () http://typo3.org/extensions/repository/view/sr_feuser_register/2.5.21/ - Patch, Vendor Advisory () http://typo3.org/extensions/repository/view/sr_feuser_register/2.5.21/ - Patch, Vendor Advisory
References () http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-004/ - Patch, Vendor Advisory () http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-004/ - Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/34374 - Patch () http://www.securityfocus.com/bid/34374 - Patch
References () http://www.vupen.com/english/advisories/2009/0938 - Patch, Vendor Advisory () http://www.vupen.com/english/advisories/2009/0938 - Patch, Vendor Advisory

Information

Published : 2009-04-07 23:30

Updated : 2024-11-21 01:02


NVD link : CVE-2009-1264

Mitre link : CVE-2009-1264

CVE.ORG link : CVE-2009-1264


JSON object : View

Products Affected

stanislas_rolland

  • sr_feuser_register

typo3

  • typo3
CWE
CWE-264

Permissions, Privileges, and Access Controls