Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2010-5104

Опубликовано: 21 мая 2012
Источник: ubuntu
Приоритет: medium
CVSS2: 4.3

Описание

The escapeStrForLike method in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 does not properly escape input when the MySQL database is set to sql_mode NO_BACKSLASH_ESCAPES, which allows remote attackers to obtain sensitive information via wildcard characters in a LIKE query.

РелизСтатусПримечание
devel

not-affected

hardy

ignored

end of life
lucid

ignored

end of life
natty

not-affected

4.3.9+dfsg1-1
oneiric

not-affected

precise

not-affected

quantal

not-affected

raring

not-affected

saucy

not-affected

upstream

released

4.3.9,4.4.5

Показывать по

4.3 Medium

CVSS2

Связанные уязвимости

nvd
больше 13 лет назад

The escapeStrForLike method in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 does not properly escape input when the MySQL database is set to sql_mode NO_BACKSLASH_ESCAPES, which allows remote attackers to obtain sensitive information via wildcard characters in a LIKE query.

debian
больше 13 лет назад

The escapeStrForLike method in TYPO3 4.2.x before 4.2.16, 4.3.x before ...

github
больше 3 лет назад

TYPO3 Sensitive Information Disclosure via escapeStrForLike method

4.3 Medium

CVSS2