CVE-2009-2106 Information

Description

SQL injection vulnerability in the Virtual Civil Services (civserv) extension 4.3.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Reference

http://osvdb.org/55121 http://secunia.com/advisories/35479 http://typo3.org/extensions/repository/view/civserv/4.3.3/ http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-007/ http://www.securityfocus.com/bid/35395

Share on: