Vulnerabilities > CVE-2012-3530 - Unspecified vulnerability in Typo3
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN typo3
nessus
Summary
Incomplete blacklist vulnerability in the t3lib_div::quoteJSvalue API function in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote attackers to conduct cross-site scripting (XSS) attacks via certain HTML5 JavaScript events.
Vulnerable Configurations
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-2537.NASL |
description | Several vulnerabilities were discovered in TYPO3, a content management system. - CVE-2012-3527 An insecure call to unserialize in the help system enables arbitrary code execution by authenticated users. - CVE-2012-3528 The TYPO3 backend contains several cross-site scripting vulnerabilities. - CVE-2012-3529 Authenticated users who can access the configuration module can obtain the encryption key, allowing them to escalate their privileges. - CVE-2012-3530 The RemoveXSS HTML sanitizer did not remove several HTML5 JavaScript, thus failing to mitigate the impact of cross-site scripting vulnerabilities. |
last seen | 2020-03-17 |
modified | 2012-08-31 |
plugin id | 61735 |
published | 2012-08-31 |
reporter | This script is Copyright (C) 2012-2020 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/61735 |
title | Debian DSA-2537-1 : typo3-src - several vulnerabilities |
code |
|
Seebug
bulletinFamily | exploit |
description | CVE ID:CVE-2012-3530 TYPO3是一个免费开源的内容管理系统。 TYPO3 t3lib_div::quoteJSvalue API函数存在不完整黑名单漏洞,允许远程攻击者利用漏洞通过某些HTML5 JavaScript事件注入任意WEB脚本或者HTML,可获得敏感信息或劫持用户会话。 0 TYPO3 4.5.x TYPO3 4.6.x TYPO3 4.7.x 厂商解决方案 用户可参考如下供应商提供的安全公告获得补丁信息: http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2012-004/ |
id | SSV:60376 |
last seen | 2017-11-19 |
modified | 2012-09-09 |
published | 2012-09-09 |
reporter | Root |
title | TYPO3 不完整黑名单跨站脚本漏洞(CVE-2012-3530) |
References
- http://osvdb.org/84772
- http://osvdb.org/84772
- http://secunia.com/advisories/50287
- http://secunia.com/advisories/50287
- http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2012-004/
- http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2012-004/
- http://www.debian.org/security/2012/dsa-2537
- http://www.debian.org/security/2012/dsa-2537
- http://www.openwall.com/lists/oss-security/2012/08/22/8
- http://www.openwall.com/lists/oss-security/2012/08/22/8
- https://exchange.xforce.ibmcloud.com/vulnerabilities/77794
- https://exchange.xforce.ibmcloud.com/vulnerabilities/77794