Summary
The remote host is missing an update to typo3-src
announced via advisory DSA 2445-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%202445-1
Insight
Several remote vulnerabilities have been discovered in the TYPO3 web content management framework:
CVE-2012-1606
Failing to properly HTML-encode user input in several places, the TYPO3 backend is susceptible to Cross-Site Scripting. A valid backend user is required to exploit these
vulnerabilities.
CVE-2012-1607
Accessing a CLI Script directly with a browser may disclose the database name used for the TYPO3 installation.
CVE-2012-1608
By not removing non printable characters, the API method t3lib_div::RemoveXSS() fails to filter specially crafted HTML injections, thus is susceptible to Cross-Site Scripting.
For the stable distribution (squeeze), these problems have been fixed in version 4.3.9+dfsg1-1+squeeze3.
For the testing distribution (wheezy) and the unstable distribution (sid), these problems have been fixed in version 4.5.14+dfsg1-1.
We recommend that you upgrade your typo3-src packages.
Severity
Classification
-
CVE CVE-2012-1606, CVE-2012-1607, CVE-2012-1608 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
Related Vulnerabilities