Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-6145

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2008-6145
Last Modified 07 Mar 2011 10:15:47
Published 16 Feb 2009 12:30:04
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2008-6145

Summary

Multiple SQL injection vulnerabilities in the WEC Discussion Forum (wec_discussion) extension 1.7.0 and earlier for TYPO3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

Vulnerable Systems

Application

  • Typo3 Wec Discussion Forum 1.6

  • Typo3 Wec Discussion Forum 1.6.0

  • Typo3 Wec Discussion Forum 1.6.1

  • Typo3 Wec Discussion Forum 1.6.2

  • Typo3 Wec Discussion Forum 1.6.3

  • Typo3 Wec Discussion Forum 1.7.0


References

CONFIRM - http://typo3.org/teams/security/security-bulletins/typo3-20081222-2

VUPEN - ADV-2008-3502

SECUNIA - 33254


Last Updated: 27 May 2016 10:49:05