CVE-2011-1722 Information

Description

Multiple SQL injection vulnerabilities in WEC Discussion Forum (wec_discussion) extension 2.1.0 and earlier for TYPO3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors as exploited in the wild in April 2011.

Reference

http://osvdb.org/71674 http://secunia.com/advisories/44055 http://typo3.org/extensions/repository/view/wec_discussion/2.1.1/ http://typo3.org/teams/security/security-bulletins/typo3-sa-2011-003/ http://www.securityfocus.com/bid/47257 http://www.vupen.com/english/advisories/2011/0896 https://exchange.xforce.ibmcloud.com/vulnerabilities/66619

Share on: