Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) content of indexed files to the (a) Indexed Search Engine (indexed_search) system extension; (b) unspecified test scripts in the ADOdb system extension; and (c) unspecified vectors in the Workspace module.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Typo3 多个跨站脚本攻击漏洞
Vulnerability Description
Typo3是开源内容管理系统(CMS)。 TYPO3 (4.0.0-4.0.9,4.1.0-4.1.7,4.2.0-4.2.3)存在多个跨站脚本攻击漏洞。 远程攻击者可以借助被变址的文件的名字和内容,注入任意的web脚本或HTML。这些文件是对(a)被变址的搜索引擎系统扩展名;(b)ADOdb系统扩展名中的未明试验脚本以及(c)Workspace模块中的未明向量的文件。
CVSS Information
N/A
Vulnerability Type
N/A