ソフト名:TYPO3 Questionnaire 2.2.2, TYPO3 Branchenbuch [Yellow Pages] (mh_branchenbuch) 0.9.0, TYPO3 Event (event) 0.3.4, TYPO3 Fe user statistic (festat) 0.2.0, TYPO3 JW Calendar (jw_calendar) 1.3.20, TYPO3 Webkit PDFs (webkitpdf) 1.1.3, TYPO3 xaJax Shoutbox (vx_xajax_shoutbox) 1.0.0
回避策:TYPO3-SA-2010-015にて対応
脆弱性:SQLインジェクション, XSS, リモートコード実行, リモートコマンド実行, 認証資格情報の奪取
ソース:http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-015/
http://www.securityfocus.com/bid/42365
http://www.securityfocus.com/bid/42366
http://www.securityfocus.com/bid/42369
http://www.securityfocus.com/bid/42373
http://www.securityfocus.com/bid/42380
http://www.securityfocus.com/bid/42381
http://secunia.com/advisories/40950
http://secunia.com/advisories/40951
危険性:High Risk
2010-08-17
登録:
コメントの投稿 (Atom)
0 件のコメント:
コメントを投稿