Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Stano Paska

#14425de 53,635
18.6CVSS total
Vulnerabilidades · 3
Média
2
Alta
1
PT-2014-7141
4.3
2014-10-03
Typo3 · Typo3 Mm Forum Extension · CVE-2014-6297
**Name of the Vulnerable Software and Affected Versions** TYPO3 mm forum extension versions prior to 1.9.3 **Description** A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML. **Recommendations** For versions prior to 1.9.3, update to version 1.9.3 or later to resolve the issue.
PT-2014-7142
7.5
2014-10-03
Typo3 · Mm Forum · CVE-2014-6298
**Name of the Vulnerable Software and Affected Versions** TYPO3 mm forum extension versions prior to 1.9.3 **Description** The issue allows remote attackers to execute arbitrary code by uploading a file with an executable extension. This is achieved by accessing the uploaded file via unspecified vectors. **Recommendations** For versions prior to 1.9.3, update to version 1.9.3 or later to resolve the issue. As a temporary workaround, consider restricting file uploads to prevent exploitation until the update is applied.
PT-2014-7143
6.8
2014-10-03
Typo3 · Typo3 Mm Forum Extension · CVE-2014-6299
**Name of the Vulnerable Software and Affected Versions** TYPO3 mm forum extension versions prior to 1.9.3 **Description** A cross-site request forgery (CSRF) issue allows remote attackers to hijack user authentication for creating posts. **Recommendations** For versions prior to 1.9.3, update to version 1.9.3 or later to resolve the issue.