4.3
CVSSv2

CVE-2008-2718

Published: 16/06/2008 Updated: 11/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in fe_adminlib.inc in TYPO3 4.0.x prior to 4.0.9, 4.1.x prior to 4.1.7, and 4.2.x prior to 4.2.1, as used in extensions such as (1) direct_mail_subscription, (2) feuser_admin, and (3) kb_md5fepw, allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

typo3 typo3 4.0.1

typo3 typo3 4.0.2

typo3 typo3 4.1.1

typo3 typo3 4.1.2

typo3 typo3 4.0.3

typo3 typo3 4.0.4

typo3 typo3 4.1.3

typo3 typo3 4.1.4

typo3 typo3 4.0.5

typo3 typo3 4.0.6

typo3 typo3 4.1.5

typo3 typo3 4.1.6

typo3 typo3 4.0

typo3 typo3 4.0.7

typo3 typo3 4.0.8

typo3 typo3 4.1

typo3 typo3 4.2

Vendor Advisories

Several remote vulnerabilities have been discovered in the TYPO3 content management framework Because of a not sufficiently secure default value of the TYPO3 configuration variable fileDenyPattern, authenticated backend users could upload files that allowed to execute arbitrary code as the webserver user User input processed by fe_adminlibinc is ...