Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
typo3 typo3 4.2 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2008-2718
Cross-site scripting (XSS) vulnerability in fe_adminlib.inc in TYPO3 4.0.x prior to 4.0.9, 4.1.x prior to 4.1.7, and 4.2.x prior to 4.2.1, as used in extensions such as (1) direct_mail_subscription, (2) feuser_admin, and (3) kb_md5fepw, allows remote malicious users to inject arb...
Typo3 Typo3 4.1.1
Typo3 Typo3 4.1
Typo3 Typo3 4.2
Typo3 Typo3 4.1.6
Typo3 Typo3 4.0.5
Typo3 Typo3 4.0.3
Typo3 Typo3 4.1.4
Typo3 Typo3 4.0.4
Typo3 Typo3 4.0.1
Typo3 Typo3 4.0.2
Typo3 Typo3 4.0.7
Typo3 Typo3 4.0
Typo3 Typo3 4.0.8
Typo3 Typo3 4.1.3
Typo3 Typo3 4.0.6
Typo3 Typo3 4.1.5
Typo3 Typo3 4.1.2
NA
CVE-2008-2717
TYPO3 4.0.x prior to 4.0.9, 4.1.x prior to 4.1.7, and 4.2.x prior to 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which allows remote malicious users to bypass security restrictions and upload configuration files such as .htaccess, or conduct file...
Typo3 Typo3 4.1.1
Typo3 Typo3 4.1
Typo3 Typo3 4.2
Typo3 Typo3 4.1.6
Typo3 Typo3 4.0.5
Typo3 Typo3 4.0.3
Typo3 Typo3 4.1.4
Typo3 Typo3 4.0.4
Typo3 Typo3 4.0.1
Typo3 Typo3 4.0.2
Typo3 Typo3 4.0.7
Typo3 Typo3 4.0
Typo3 Typo3 4.0.8
Typo3 Typo3 4.1.3
Apache Apache Webserver
Typo3 Typo3 4.0.6
Typo3 Typo3 4.1.5
Typo3 Typo3 4.1.2
NA
CVE-2009-0815
The jumpUrl mechanism in class.tslib_fe.php in TYPO3 3.3.x up to and including 3.8.x, 4.0 prior to 4.0.12, 4.1 prior to 4.1.10, 4.2 prior to 4.2.6, and 4.3alpha1 leaks a hash secret (juHash) in an error message, which allows remote malicious users to read arbitrary files by inclu...
Typo3 Typo3 4.3
Typo3 Typo3 3.5.x
Typo3 Typo3 4.2.4
Typo3 Typo3 4.1
Typo3 Typo3 4.2
Typo3 Typo3 4.2.5
Typo3 Typo3 4.1.8
Typo3 Typo3 4.1.6
Typo3 Typo3 4.2.0
Typo3 Typo3 4.2.3
Typo3 Typo3 4.1.4
Typo3 Typo3 3.7.x
Typo3 Typo3 4.2.1
Typo3 Typo3 4.1.7
Typo3 Typo3 4.1.0
Typo3 Typo3 4.0
Typo3 Typo3 4.1.9
Typo3 Typo3 4.2.2
Typo3 Typo3 3.8.x
Typo3 Typo3 3.6.x
Typo3 Typo3 3.3.x
Typo3 Typo3 4.1.3
1 EDB exploit
NA
CVE-2009-0816
Multiple cross-site scripting (XSS) vulnerabilities in the backend user interface in TYPO3 3.3.x up to and including 3.8.x, 4.0 prior to 4.0.12, 4.1 prior to 4.1.10, 4.2 prior to 4.2.6, and 4.3alpha1 allow remote malicious users to inject arbitrary web script or HTML via unspecif...
Typo3 Typo3 4.1.1
Typo3 Typo3 4.2.4
Typo3 Typo3 4.1
Typo3 Typo3 4.2
Typo3 Typo3 4.2.5
Typo3 Typo3 4.1.8
Typo3 Typo3 4.1.6
Typo3 Typo3 4.0.10
Typo3 Typo3 4.0.5
Typo3 Typo3 4.0.3
Typo3 Typo3 4.2.3
Typo3 Typo3 4.1.4
Typo3 Typo3 4.0.4
Typo3 Typo3 4.2.1
Typo3 Typo3 4.0.1
Typo3 Typo3 4.1.7
Typo3 Typo3 4.0.2
Typo3 Typo3 4.0.7
Typo3 Typo3 4.0
Typo3 Typo3 4.1.9
Typo3 Typo3 4.2.2
Typo3 Typo3 4.0.8
NA
CVE-2010-5098
Cross-site scripting (XSS) vulnerability in the FORM content object in TYPO3 4.2.x prior to 4.2.16, 4.3.x prior to 4.3.9, and 4.4.x prior to 4.4.5, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Typo3 Typo3 4.2.10
Typo3 Typo3 4.3.6
Typo3 Typo3 4.2.14
Typo3 Typo3 4.3.5
Typo3 Typo3 4.3.8
Typo3 Typo3 4.2.4
Typo3 Typo3 4.2
Typo3 Typo3 4.2.5
Typo3 Typo3 4.2.15
Typo3 Typo3 4.2.11
Typo3 Typo3 4.2.0
Typo3 Typo3 4.3.7
Typo3 Typo3 4.2.8
Typo3 Typo3 4.2.13
Typo3 Typo3 4.2.3
Typo3 Typo3 4.4.4
Typo3 Typo3 4.2.1
Typo3 Typo3 4.3
Typo3 Typo3 4.3.2
Typo3 Typo3 4.4.1
Typo3 Typo3 4.4.2
Typo3 Typo3 4.2.12
NA
CVE-2010-5100
Multiple cross-site scripting (XSS) vulnerabilities in the Install Tool in TYPO3 4.2.x prior to 4.2.16, 4.3.x prior to 4.3.9, and 4.4.x prior to 4.4.5 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Typo3 Typo3 4.2.10
Typo3 Typo3 4.3.6
Typo3 Typo3 4.2.14
Typo3 Typo3 4.3.5
Typo3 Typo3 4.3.8
Typo3 Typo3 4.2.4
Typo3 Typo3 4.2
Typo3 Typo3 4.2.5
Typo3 Typo3 4.2.15
Typo3 Typo3 4.2.11
Typo3 Typo3 4.2.0
Typo3 Typo3 4.3.7
Typo3 Typo3 4.2.8
Typo3 Typo3 4.2.13
Typo3 Typo3 4.2.3
Typo3 Typo3 4.4.4
Typo3 Typo3 4.2.1
Typo3 Typo3 4.3
Typo3 Typo3 4.3.2
Typo3 Typo3 4.4.1
Typo3 Typo3 4.4.2
Typo3 Typo3 4.2.12
NA
CVE-2010-5102
Directory traversal vulnerability in mod/tools/em/class.em_unzip.php in the unzip library in TYPO3 4.2.x prior to 4.2.16, 4.3.x prior to 4.3.9, and 4.4.x prior to 4.4.5 allows remote malicious users to write arbitrary files via unspecified vectors.
Typo3 Typo3 4.2.10
Typo3 Typo3 4.3.6
Typo3 Typo3 4.2.14
Typo3 Typo3 4.3.5
Typo3 Typo3 4.3.8
Typo3 Typo3 4.2.4
Typo3 Typo3 4.2.5
Typo3 Typo3 4.2.15
Typo3 Typo3 4.2.11
Typo3 Typo3 4.2.0
Typo3 Typo3 4.3.7
Typo3 Typo3 4.2.8
Typo3 Typo3 4.2.13
Typo3 Typo3 4.2.3
Typo3 Typo3 4.4.4
Typo3 Typo3 4.2.1
Typo3 Typo3 4.3.2
Typo3 Typo3 4.4.1
Typo3 Typo3 4.4.2
Typo3 Typo3 4.2.12
Typo3 Typo3 4.2.6
Typo3 Typo3 4.3.0
NA
CVE-2010-5103
SQL injection vulnerability in the list module in TYPO3 4.2.x prior to 4.2.16, 4.3.x prior to 4.3.9, and 4.4.x prior to 4.4.5 allows remote authenticated users with certain permissions to execute arbitrary SQL commands via unspecified vectors.
Typo3 Typo3 4.2.10
Typo3 Typo3 4.3.6
Typo3 Typo3 4.2.14
Typo3 Typo3 4.3.5
Typo3 Typo3 4.3.8
Typo3 Typo3 4.2.4
Typo3 Typo3 4.2.5
Typo3 Typo3 4.2.15
Typo3 Typo3 4.2.11
Typo3 Typo3 4.2.0
Typo3 Typo3 4.3.7
Typo3 Typo3 4.2.8
Typo3 Typo3 4.2.13
Typo3 Typo3 4.2.3
Typo3 Typo3 4.4.4
Typo3 Typo3 4.2.1
Typo3 Typo3 4.3.2
Typo3 Typo3 4.4.1
Typo3 Typo3 4.4.2
Typo3 Typo3 4.2.12
Typo3 Typo3 4.2.6
Typo3 Typo3 4.3.0
NA
CVE-2010-5101
Directory traversal vulnerability in the TypoScript setup in TYPO3 4.2.x prior to 4.2.16, 4.3.x prior to 4.3.9, and 4.4.x prior to 4.4.5 allows remote authenticated administrators to read arbitrary files via unspecified vectors related to the "file inclusion functionality.&q...
Typo3 Typo3 4.2.10
Typo3 Typo3 4.3.6
Typo3 Typo3 4.2.14
Typo3 Typo3 4.3.5
Typo3 Typo3 4.3.8
Typo3 Typo3 4.2.4
Typo3 Typo3 4.2.5
Typo3 Typo3 4.2.15
Typo3 Typo3 4.2.11
Typo3 Typo3 4.2.0
Typo3 Typo3 4.3.7
Typo3 Typo3 4.2.8
Typo3 Typo3 4.2.13
Typo3 Typo3 4.2.3
Typo3 Typo3 4.4.4
Typo3 Typo3 4.2.1
Typo3 Typo3 4.3.2
Typo3 Typo3 4.4.1
Typo3 Typo3 4.4.2
Typo3 Typo3 4.2.12
Typo3 Typo3 4.2.6
Typo3 Typo3 4.3.0
NA
CVE-2010-4068
Unspecified vulnerability in the Extension Manager in TYPO3 4.2.x prior to 4.2.15, 4.3.x prior to 4.3.7, and 4.4.x prior to 4.4.4 allows remote authenticated administrators to read and possibly modify arbitrary files via a crafted parameter, a different vulnerability than CVE-201...
Typo3 Typo3 4.2.10
Typo3 Typo3 4.3.6
Typo3 Typo3 4.2.14
Typo3 Typo3 4.3.5
Typo3 Typo3 4.2.4
Typo3 Typo3 4.2.5
Typo3 Typo3 4.2.11
Typo3 Typo3 4.2.0
Typo3 Typo3 4.2.8
Typo3 Typo3 4.2.13
Typo3 Typo3 4.2.3
Typo3 Typo3 4.2.1
Typo3 Typo3 4.3.2
Typo3 Typo3 4.4.1
Typo3 Typo3 4.4.2
Typo3 Typo3 4.2.12
Typo3 Typo3 4.2.6
Typo3 Typo3 4.3.0
Typo3 Typo3 4.2.2
Typo3 Typo3 4.3.3
Typo3 Typo3 4.3.4
Typo3 Typo3 4.4
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
type confusion
IMAP
CVE-2024-36103
CVE-2024-28995
CVE-2024-37325
CVE-2024-30078
CVE-2024-30082
SQL injection
CVE-2024-30052
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »