Release date:
Updated on: 2013-02-21
Affected Systems:
TYPO3 My quiz and poll Extension 2.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 58057
TYPO3 My quiz and poll Extension is a versatile advanced test plug-in that can be used for testing, investigating, voting, rating, or psychological testing.
My quiz and poll 2.0.0 and earlier versions are used in SQL queries or returned to users without filtering some input. By injecting arbitrary SQL code, operations on SQL queries can be performed, or execute arbitrary HTML and script code in the context of the affected site.
<* Source: Robert Presedo
Link: http://secunia.com/advisories/52285/
Http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2013-005/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
TYPO3
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://typo3.org/extensions/repository/view/myquizpoll