Lucene search

K
ubuntucveUbuntu.comUB:CVE-2014-9508
HistoryJan 04, 2015 - 12:00 a.m.

CVE-2014-9508

2015-01-0400:00:00
ubuntu.com
ubuntu.com
24

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.002

Percentile

56.9%

The frontend rendering component in TYPO3 4.5.x before 4.5.39, 4.6.x
through 6.2.x before 6.2.9, and 7.x before 7.0.2, when
config.prefixLocalAnchors is set and using a homepage with links that only
contain anchors, allows remote attackers to change URLs to arbitrary
domains for those links via unknown vectors.

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.002

Percentile

56.9%