Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-6144

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2008-6144
Last Modified 07 Mar 2011 10:15:47
Published 16 Feb 2009 12:30:04
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2008-6144

Summary

Multiple cross-site scripting (XSS) vulnerabilities in the WEC Discussion Forum (wec_discussion) extension 1.7.0 and earlier for TYPO3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2008-3029.

Vulnerable Systems

Application

  • Typo3 Wec Discussion Forum 1.6

  • Typo3 Wec Discussion Forum 1.6.0

  • Typo3 Wec Discussion Forum 1.6.1

  • Typo3 Wec Discussion Forum 1.6.2

  • Typo3 Wec Discussion Forum 1.6.3

  • Typo3 Wec Discussion Forum 1.7.0


References

CONFIRM - http://typo3.org/teams/security/security-bulletins/typo3-20081222-2

VUPEN - ADV-2008-3502

SECUNIA - 33254


Last Updated: 27 May 2016 10:49:05