CVE-2010-0329 Information

Description

SQL injection vulnerability in the powermail extension 1.5.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to the \SQL selection field\ and \typoscript.\

Reference

http://secunia.com/advisories/38167 http://typo3.org/extensions/repository/view/powermail/1.5.2/ http://typo3.org/extensions/repository/view/powermail/1.5.2/info/changelog.txt/ http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-021/

Share on: