TYPO3 Commenting system Backend Module Unspecified SQL Injection issue

Saturday, October 9, 2010


Commenting system Backend Module "commentsbe" is an extension for the TYPO3 content manager. The extension is exposed to an unspecified SQL injection issue because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. Commenting system Backend Module 0.0.2 and prior are affected.

Ref: http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-018/

10.40.30 - CVE: Not Available
Platform: Web Application - SQL Injection

0 comments:

Most Recent Post

MORE ON ARCHIVE
Widget by Mad Tomato

Help Me Expose This Article in Bulk!

Bookmark & Share

- OR -

SELECT YOUR PREFERRED ONE:

Bookmark and Share