Lucene search

K
cveRedhatCVE-2012-1608
HistorySep 04, 2012 - 8:55 p.m.

CVE-2012-1608

2012-09-0420:55:01
CWE-20
redhat
web.nvd.nist.gov
43
typo3
t3lib_div
removexss
xss protection
web script injection
cve-2012-1608
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

5.5

Confidence

High

EPSS

0.002

Percentile

58.5%

The t3lib_div::RemoveXSS API method in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and inject arbitrary web script or HTML via non printable characters.

Affected configurations

Nvd
Node
typo3typo3Match4.4.0
OR
typo3typo3Match4.4.1
OR
typo3typo3Match4.4.2
OR
typo3typo3Match4.4.3
OR
typo3typo3Match4.4.4
OR
typo3typo3Match4.4.5
OR
typo3typo3Match4.4.6
OR
typo3typo3Match4.4.7
OR
typo3typo3Match4.4.8
OR
typo3typo3Match4.4.9
OR
typo3typo3Match4.4.10
OR
typo3typo3Match4.4.11
OR
typo3typo3Match4.4.12
OR
typo3typo3Match4.4.13
OR
typo3typo3Match4.5.0
OR
typo3typo3Match4.5.1
OR
typo3typo3Match4.5.2
OR
typo3typo3Match4.5.3
OR
typo3typo3Match4.5.4
OR
typo3typo3Match4.5.5
OR
typo3typo3Match4.5.6
OR
typo3typo3Match4.5.7
OR
typo3typo3Match4.5.8
OR
typo3typo3Match4.5.9
OR
typo3typo3Match4.5.10
OR
typo3typo3Match4.5.11
OR
typo3typo3Match4.5.12
OR
typo3typo3Match4.5.13
OR
typo3typo3Match4.6.0
OR
typo3typo3Match4.6.1
OR
typo3typo3Match4.6.2
OR
typo3typo3Match4.6.3
OR
typo3typo3Match4.6.4
OR
typo3typo3Match4.6.5
OR
typo3typo3Match4.6.6
OR
typo3typo3Match4.7
OR
typo3typo3Match6.0
VendorProductVersionCPE
typo3typo34.4.0cpe:2.3:a:typo3:typo3:4.4.0:*:*:*:*:*:*:*
typo3typo34.4.1cpe:2.3:a:typo3:typo3:4.4.1:*:*:*:*:*:*:*
typo3typo34.4.2cpe:2.3:a:typo3:typo3:4.4.2:*:*:*:*:*:*:*
typo3typo34.4.3cpe:2.3:a:typo3:typo3:4.4.3:*:*:*:*:*:*:*
typo3typo34.4.4cpe:2.3:a:typo3:typo3:4.4.4:*:*:*:*:*:*:*
typo3typo34.4.5cpe:2.3:a:typo3:typo3:4.4.5:*:*:*:*:*:*:*
typo3typo34.4.6cpe:2.3:a:typo3:typo3:4.4.6:*:*:*:*:*:*:*
typo3typo34.4.7cpe:2.3:a:typo3:typo3:4.4.7:*:*:*:*:*:*:*
typo3typo34.4.8cpe:2.3:a:typo3:typo3:4.4.8:*:*:*:*:*:*:*
typo3typo34.4.9cpe:2.3:a:typo3:typo3:4.4.9:*:*:*:*:*:*:*
Rows per page:
1-10 of 371

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

5.5

Confidence

High

EPSS

0.002

Percentile

58.5%