Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-3530

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2012-3530
Last Modified 06 Nov 2012 12:14:03
Published 05 Sep 2012 07:55:02
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2012-3530

Summary

Incomplete blacklist vulnerability in the t3lib_div::quoteJSvalue API function in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote attackers to conduct cross-site scripting (XSS) attacks via certain HTML5 JavaScript events.

Vulnerable Systems

Application

  • Typo3 4.5

  • Typo3 4.5.0

  • Typo3 4.5.1

  • Typo3 4.5.10

  • Typo3 4.5.11

  • Typo3 4.5.12

  • Typo3 4.5.13

  • Typo3 4.5.14

  • Typo3 4.5.15

  • Typo3 4.5.16

  • Typo3 4.5.17

  • Typo3 4.5.18

  • Typo3 4.5.2

  • Typo3 4.5.3

  • Typo3 4.5.4

  • Typo3 4.5.5

  • Typo3 4.5.6

  • Typo3 4.5.7

  • Typo3 4.5.8

  • Typo3 4.5.9

  • Typo3 4.6

  • Typo3 4.6.0

  • Typo3 4.6.1

  • Typo3 4.6.10

  • Typo3 4.6.11

  • Typo3 4.6.2

  • Typo3 4.6.3

  • Typo3 4.6.4

  • Typo3 4.6.5

  • Typo3 4.6.6

  • Typo3 4.6.7

  • Typo3 4.6.8

  • Typo3 4.6.9

  • Typo3 4.7

  • Typo3 4.7.0

  • Typo3 4.7.1

  • Typo3 4.7.2

  • Typo3 4.7.3


References

XF - typo3-html5-xss(77794)

MLIST - [oss-security] 20120822 Re: CVE request: Typo3

CONFIRM - http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2012-004/

SECUNIA - 50287

OSVDB - 84772

DEBIAN - DSA-2537


Last Updated: 27 May 2016 11:00:28