Multiple Vulnerabilities in Multiple TYPO3 Extensions
TYPO3 is an enterprise-level open source content management system.
Affected Application: The TYPO3 extensions Webkit PDFs (webkitpdf) versions before 1.1.4, and Questionnaire (k3_questionnaire) versions before 2.2.3.
Issue: On 10/09/11, cross-site scripting and SQL injection vulnerabilities were reported for the TYPO3 extensions webkitpdf and k3_questionnaire. The vulnerabilities let attackers inject code to steal cookie-based data or other sensitive information, and perform other malicious actions.
Resolution: An update for TYPO3 is available. Visit the vendor's website for information: http://typo3.com/.
This information was compiled using information in the National Vulnerability Database. For more information about this issue, see the following summaries:
CVE-2010-4961
CVE-2010-4957
CVE-2010-4956
To learn more about cross-site scripting vulnerabilities, see Cross-Site Scripting. To learn more about SQL injection vulnerabilities, see Injection Flaws.
Website Protection Site Scanner scans for this vulnerability, and many more. To learn about Site Scanner, see Getting Started with Website Protection Site Scanner.