Released on: 2013-06-03
Updated on: 2013-06-26
Affected Systems:
TYPO3 multihop <2.0.39
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2013-4681
Typo3 is an open-source Content Management System (CMS) and Content Management Framework (CMF ).
Sofortueberweisung2commerce 2.0.1 and earlier versions of TYPO3 have the SQL injection vulnerability. Attackers exploit this vulnerability to destroy applications, access or modify data, exploit other vulnerabilities in the underlying database, and execute SQL commands.
<* Source: Thomas Luzat
Link: http://secunia.com/advisories/53280
Http://xforce.iss.net/xforce/xfdb/81585
Http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2013-002/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
TYPO3
-----
TYPO3 has released a Security Bulletin (typo3-ext-sa-2013-002) and corresponding patches for this:
Typo3-ext-sa-2013-002: TYPO3-EXT-SA-2013-002: Several vulnerabilities in third party extensions
Link: http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2013-002/
Patch download: http://typo3.org/extensions/repository/view/sofortueberweisung2commerce/2.0.1/