Описание
Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the "JSwindow" property of the typolink function.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 4.5.10+dfsg1-1 |
| hardy | ignored | end of life |
| lucid | ignored | end of life |
| maverick | ignored | end of life |
| natty | released | 4.3.9+dfsg1-1+squeeze1build0.11.04.1 |
| oneiric | ignored | end of life |
| precise | not-affected | 4.5.10+dfsg1-1 |
| quantal | not-affected | 4.5.10+dfsg1-1 |
| raring | not-affected | 4.5.10+dfsg1-1 |
| saucy | not-affected | 4.5.10+dfsg1-1 |
Показывать по
4.3 Medium
CVSS2
6.1 Medium
CVSS3
Связанные уязвимости
Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the "JSwindow" property of the typolink function.
Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, ...
Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the "JSwindow" property of the typolink function.
4.3 Medium
CVSS2
6.1 Medium
CVSS3