Released on: 2013-06-03
Updated on: 2013-06-26
Affected Systems:
TYPO3 meta_feedit <= 0.1.10
Description:
--------------------------------------------------------------------------------
Bugtraq id: 60296
CVE (CAN) ID: CVE-2013-4683
Typo3 is an open-source Content Management System (CMS) and Content Management Framework (CMF ).
Meta_feedit 0.1.10 and earlier versions of TYPO3 have the SQL injection vulnerability. Attackers can exploit this vulnerability to destroy applications, access or modify data, exploit other vulnerabilities in the underlying database, and execute SQL commands.
<* Source: Clemens Riccabona
Link: http://xforce.iss.net/xforce/xfdb/84661
Http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2013-007/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
TYPO3
-----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://typo3.org/extensions/repository/