TYPO3多个扩展跨站脚本及SQL注入漏洞

Posted by ArtHack on Jun 23rd, 2008 and filed under Notice loopholes. You can follow any responses to this entry through the RSS 2.0. You can also subscribe to us, through the Top of the E-mail - 加入超级QQ群:32843311

受影响系统:
TYPO3 TYPO3
描述:
——————————————————————————–
BUGTRAQ  ID: 29837,29833,29832,29828,29827,29826,29825,29824,29823,29822,29821,29819,29815

Typo3是开源内容管理系统(CMS)和内容管理框架(CMF)。

Typo3的TARGET-E WorldCup Bets(worldcup)、TIMTAB(timtab_sociable)、Download system(sb_downloader)、JobControl(dmmjobcontrol)和CoolURI(cooluri)扩展中存在SQL 注入漏洞,TARGET-E WorldCup Bets(worldcup)、JobControl(dmmjobcontrol)和DCD GoogleMap(dcdgooglemap)扩展中存在跨站脚本漏洞。远程攻击者可以通过向服务器提交恶意请求导致执行SQL注入攻击或在用户浏览器 中执行任意代码。

<*来源:Martin Holtz

链接:http://secunia.com/advisories/30737/
http://secunia.com/advisories/30773/
http://typo3.org/teams/security/security-bulletins/typo3-20080619-1/
*>

建议:
——————————————————————————–
厂商补丁:

TYPO3
—–
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:

http://typo3.org/teams/security/security-bulletins/typo3-20080619-1/

Classic Posts

Our Sponsors

Leave a Reply

Our Sponsors

Tag Cloud

Premium Wordpress Themes

WooThemes
StudioPress
Template Monster
Themeforest
StyleWP
Translator
Chinese (Simplified) flagChinese (Traditional) flagItalian flagKorean flagPortuguese flagEnglish flagGerman flagFrench flagSpanish flagJapanese flagArabic flagRussian flagGreek flagDutch flagBulgarian flagCzech flagCroat flagDanish flagFinnish flagHindi flagPolish flagRumanian flagSwedish flagNorwegian flagCatalan flagFilipino flagHebrew flagIndonesian flagLatvian flagLithuanian flagSerbian flagSlovak flagSlovenian flagUkrainian flagVietnamese flagAlbanian flagEstonian flagGalician flagMaltese flagThai flagTurkish flagHungarian flag
Log in / Art Hack.All rights reserved.