SQL injection vulnerability in the Statistics (ke_stats) extension before 1.1.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, as exploited in the wild in February 2014.
References
Configurations
History
21 Nov 2024, 02:14
Type | Values Removed | Values Added |
---|---|---|
References | () http://typo3.org/extensions/repository/view/ke_stats - | |
References | () http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2014-002/ - Vendor Advisory |
Information
Published : 2014-10-03 14:55
Updated : 2024-11-21 02:14
NVD link : CVE-2014-6293
Mitre link : CVE-2014-6293
CVE.ORG link : CVE-2014-6293
JSON object : View
Products Affected
kennziffer
- statistics
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')