2010-03-19

TYPO3

ソフト名:TYPO3 Brainstorming (brainstorming) 0.1.8, TYPO3 Power Extension Manager (ch_lightem) 1.0.34, TYPO3 Sellector.com Widget Integration (chsellector) 0.1.1, TYPO3 MK Wastebasket (mk_wastebasket) 2.1.0, TYPO3 myDashboard (mydashboard) 0.1.13, TYPO3 CleanDB (nf_cleandb) 1.0.7, TYPO3 Diocese of Portsmouth Database (pd_diocesedatabase) 0.7.12, TYPO3 Reports Logfile View (reports_logview) 1.2.1, TYPO3 SAV Filter Alphabetic (sav_filter_abc) 1.0.8, TYPO3 SAV Filter Selectors (sav_filter_selectors) 1.0.4, TYPO3 SAV Filter Months (sav_filter_months) 1.0.4, TYPO3 Book Reviews (sk_bookreview) 0.0.12, TYPO3 Simple Gallery (sk_simplegallery) 0.0.9, TYPO3 Typo3 Quixplorer (t3quixplorer) 1.7.0, TYPO3 Salted user password hashes (t3sec_saltedpw) 0.2.12, TYPO3 UserTask Center, recent (taskcenter_recent) 0.1.0, TYPO3 TGM-Newsletter (tgm_newsletter) 0.0.2, TYPO3 CleanDB - DBAL (tmsw_cleandb) 2.1.0, TYPO3 Meet Travelmates (travelmate) 0.1.1, TYPO3 YATSE - Yet another TYPO3 search engine (yatse) 0.3.1
回避策:あり
脆弱性:SQLインジェクション, 特定されていない脆弱性, 機密情報の奪取, XSS
ソース:
http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006/
http://www.securityfocus.com/bid/38792
http://www.securityfocus.com/bid/38795
http://www.securityfocus.com/bid/38796
http://www.securityfocus.com/bid/38797
http://www.securityfocus.com/bid/38798
http://www.securityfocus.com/bid/38789
http://www.securityfocus.com/bid/38799
http://www.securityfocus.com/bid/38800
http://www.securityfocus.com/bid/38801
http://www.securityfocus.com/bid/38802
http://www.securityfocus.com/bid/38803
http://www.securityfocus.com/bid/38804
http://www.securityfocus.com/bid/38805
http://www.securityfocus.com/bid/38806
http://www.securityfocus.com/bid/38808
http://www.securityfocus.com/bid/38810
http://www.securityfocus.com/bid/38811
http://www.securityfocus.com/bid/38812
http://www.securityfocus.com/bid/38816
http://www.securityfocus.com/bid/38818
http://www.securityfocus.com/bid/38823
http://secunia.com/advisories/38985
http://secunia.com/advisories/38992
http://secunia.com/advisories/38993
http://secunia.com/advisories/38994
http://secunia.com/advisories/38995
http://secunia.com/advisories/38996
危険性:Medium Risk

0 件のコメント:

コメントを投稿