Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 2 |
CVE-ID | CVE-2013-1843 CVE-2013-1842 |
CWE-ID | CWE-399 CWE-89 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software Subscribe |
TYPO3 Web applications / CMS |
Vendor | TYPO3 |
Security Bulletin
This security bulletin contains information about 2 vulnerabilities.
EUVDB-ID: #VU42982
Risk: Medium
CVSSv3.1: 5.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2013-1843
CWE-ID:
CWE-399 - Resource Management Errors
Exploit availability: No
DescriptionThe vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Open redirect vulnerability in the Access tracking mechanism in TYPO3 4.5.x before 4.5.24, 4.6.x before 4.6.17, 4.7.x before 4.7.9, and 6.0.x before 6.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
MitigationInstall update from vendor's website.
Vulnerable software versionsTYPO3: 4.5 - 6.0.2
CPE2.3 External linkshttp://lists.opensuse.org/opensuse-updates/2013-03/msg00079.html
http://secunia.com/advisories/52433
http://secunia.com/advisories/52638
http://typo3.org/support/teamssecuritysecurity-bulletins/security-bulletins-single-view/article/sql-injection-and-open-redirection-in-typo3-core/
http://www.debian.org/security/2013/dsa-2646
http://www.openwall.com/lists/oss-security/2013/03/12/3
http://www.osvdb.org/90924
http://www.securityfocus.com/bid/58330
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU42986
Risk: Medium
CVSSv3.1: 6.4 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C]
CVE-ID: CVE-2013-1842
CWE-ID:
CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can send a specially crafted request to the affected application and execute arbitrary SQL commands within the application database.
Successful exploitation of this vulnerability may allow a remote attacker to read, delete, modify data in database and gain complete control over the affected application.
MitigationInstall update from vendor's website.
Vulnerable software versionsTYPO3: 4.5 - 6.0.2
CPE2.3 External linkshttp://lists.opensuse.org/opensuse-updates/2013-03/msg00079.html
http://osvdb.org/90925
http://secunia.com/advisories/52433
http://secunia.com/advisories/52638
http://typo3.org/support/teamssecuritysecurity-bulletins/security-bulletins-single-view/article/sql-injection-and-open-redirection-in-typo3-core/
http://www.debian.org/security/2013/dsa-2646
http://www.openwall.com/lists/oss-security/2013/03/12/3
http://www.securityfocus.com/bid/58330
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.