The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a database and tools to fix them.

Vulnerability of TYPO3: vulnerabilities of extensions

Synthesis of the vulnerability

An attacker can use several vulnerabilities of TYPO3 extensions in order to generate a Cross Site Scripting or to inject code.
Severity of this computer vulnerability: 2/4.
Number of vulnerabilities in this bulletin: 7.
Creation date: 19/02/2013.
Références of this announce: BID-58054, BID-58055, BID-58056, BID-58057, BID-60939, BID-62013, CVE-2013-4720, CVE-2013-4721, CVE-2013-4746, CVE-2013-5322, CVE-2013-5323, CVE-2013-5569, TYPO3-EXT-SA-2013-003, TYPO3-EXT-SA-2013-004, TYPO3-EXT-SA-2013-005, VIGILANCE-VUL-12436.

Description of the vulnerability

Several vulnerabilities were announced in TYPO3 extensions.

An attacker can trigger an SQL injection in the CoolURI (cooluri) extension. [severity:2/4; BID-58055, CVE-2013-5322, TYPO3-EXT-SA-2013-003]

An attacker can trigger a Cross Site Scripting in the Static Info Tables (static_info_tables) extension. [severity:2/4; BID-58056, CVE-2013-5323, TYPO3-EXT-SA-2013-004]

An attacker can inject commands in the Fluid Extbase Development Framework (fed) extension. [severity:2/4; TYPO3-EXT-SA-2013-005]

An attacker can trigger an SQL injection in the WEC Discussion Forum (wec_discussion) extension. [severity:2/4; BID-58054, CVE-2013-4720, TYPO3-EXT-SA-2013-005]

An attacker can trigger an SQL injection in the RSS feed from records (push2rss_3ds) extension. [severity:2/4; CVE-2013-4721, TYPO3-EXT-SA-2013-005]

An attacker can trigger an SQL injection in the Slideshare (slideshare) extension. [severity:2/4; BID-62013, CVE-2013-5569, TYPO3-EXT-SA-2013-005]

An attacker can trigger an SQL injection and a Cross Site Scripting in the My quiz and poll (myquizpoll) extension. [severity:2/4; BID-58057, BID-60939, CVE-2013-4746, TYPO3-EXT-SA-2013-005]
Full Vigil@nce bulletin... (Free trial)

This weakness alert impacts software or systems such as TYPO3 Extensions ~ not comprehensive.

Our Vigil@nce team determined that the severity of this computer vulnerability note is medium.

The trust level is of type confirmed by the editor, with an origin of document.

This bulletin is about 7 vulnerabilities.

An attacker with a expert ability can exploit this security bulletin.

Solutions for this threat

TYPO3: corrected extensions.
The following extensions are corrected:
CoolURI (cooluri) 1.0.30
  http://typo3.org/extensions/repository/view/cooluri/1.0.30/
Static Info Tables (static_info_tables) 2.3.1
  http://typo3.org/extensions/repository/view/static_info_tables/2.3.1/
Fluid Extbase Development Framework (fed) 5.0.3
  http://typo3.org/extensions/repository/view/fed/5.0.3/
WEC Discussion Forum (wec_discussion) 2.1.2
  http://typo3.org/extensions/repository/view/wec_discussion/2.1.2/
RSS feed from records (push2rss_3ds)
  This extension is not supported anymore.
Slideshare (slideshare)
  This extension is not supported anymore.
My quiz and poll (myquizpoll) 2.0.6
  http://typo3.org/extensions/repository/view/myquizpoll/2.0.6/
Full Vigil@nce bulletin... (Free trial)

Computer vulnerabilities tracking service

Vigil@nce provides an applications vulnerabilities announce. The Vigil@nce team tracks computer vulnerabilities impacting systems and applications.