Affected Systems:
TYPO3 Jobcontrol
Describe:
--------------------------------------------------------------------------------
Bugtraq id:70145
CVE (CAN) id:cve-2014-5324
TYPO3 is an open source content management System (CMS) and Content Management Framework (CMF).
TYPO3 Jobcontrol 2.14. version 0 and previous versions there are SQL injection and cross-site scripting vulnerabilities in the implementation that could allow an attacker to exploit this vulnerability to steal cookie authentication credentials and perform unauthorized database operations.
<* Source: Yuji Tounai
*>
Suggestions:
--------------------------------------------------------------------------------
Vendor Patches:
TYPO3
-----
Currently the manufacturer has not provided a patch or upgrade program, we recommend users of this software to follow the manufacturer's homepage to get the latest version:
Http://typo3.org/extensions/repository/view/dmmjobcontrol
TYPO3 Jobcontrol SQL injection and cross-site scripting Vulnerability-China cold dragon