Secunia
|
|

CVE Reference: CVE-2009-0257 |
|
| NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE. | |
|
Original Page at CVE MITRE: CVE-2009-0257 |
|
|
Description: Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) content of indexed files to the (a) Indexed Search Engine (indexed_search) system extension; (b) unspecified test scripts in the ADOdb system extension; and (c) unspecified vectors in the Workspace module. |
|
|
CVE Status: Candidate |
|
|
References: XF http://xforce.iss.net/xforce/xfdb/48137 http://xforce.iss.net/xforce/xfdb/48135 http://xforce.iss.net/xforce/xfdb/48133 http://xforce.iss.net/xforce/xfdb/48136 SAID Secunia Advisory: SA33617 Secunia Advisory: SA33679 DEBIAN http://www.debian.org/security/2009/dsa-1711 CONFIRM http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-001/ BID 33376 |
|
| Return to the previous page. |
Not a customer already?Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance. |