Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-7080

Опубликовано: 23 дек. 2013
Источник: ubuntu
Приоритет: medium
CVSS2: 5.8

Описание

The creating record functionality in Extension table administration library (feuser_adminLib.inc) in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, and 6.0.0 through 6.0.11 allows remote attackers to write to arbitrary fields in the configuration database table via crafted links, aka "Mass Assignment."

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [4.5.32+dfsg1-1]]
lucid

ignored

end of life
precise

ignored

end of life
precise/esm

DNE

precise was needed
quantal

ignored

end of life
raring

released

4.5.19+dfsg1-5+wheezy2build0.13.04.1
saucy

ignored

end of life
trusty

not-affected

4.5.32+dfsg1-1
trusty/esm

DNE

trusty was not-affected [4.5.32+dfsg1-1]

Показывать по

5.8 Medium

CVSS2

Связанные уязвимости

nvd
около 12 лет назад

The creating record functionality in Extension table administration library (feuser_adminLib.inc) in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, and 6.0.0 through 6.0.11 allows remote attackers to write to arbitrary fields in the configuration database table via crafted links, aka "Mass Assignment."

debian
около 12 лет назад

The creating record functionality in Extension table administration li ...

github
больше 3 лет назад

TYPO3 is vulnerable to Mass Assignment in the Extension table administration library

5.8 Medium

CVSS2