Vulnerabilities > Typo3

DATE CVE VULNERABILITY TITLE RISK
2006-12-21 CVE-2006-6690 Remote Command Execution vulnerability in Typo3 Class.TX_RTEHTMLArea_PI1.PHP
rtehtmlarea/pi1/class.tx_rtehtmlarea_pi1.php in Typo3 4.0.0 through 4.0.3, 3.7 and 3.8 with the rtehtmlarea extension, and 4.1 beta allows remote authenticated users to execute arbitrary commands via shell metacharacters in the userUid parameter to rtehtmlarea/htmlarea/plugins/SpellChecker/spell-check-logic.php, and possibly another vector.
network
low complexity
typo3
7.5
2006-09-28 CVE-2006-5069 Cross-Site Scripting vulnerability in Typo3 Indexed Search
Cross-site scripting (XSS) vulnerability in class.tx_indexedsearch.php in the Indexed Search 2.9.0 extension for Typo3 before 4.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.
network
high complexity
typo3
2.6
2006-01-21 CVE-2006-0327 Information Disclosure vulnerability in Typo3 3.7.1/3.8.1
TYPO3 3.7.1 allows remote attackers to obtain sensitive information via a direct request to (1) thumbs.php, (2) showpic.php, or (3) tables.php, which causes them to incorrectly define a variable and reveal the path in an error message when a require function call fails.
network
low complexity
typo3
5.0
2005-12-31 CVE-2005-4875 Information Exposure vulnerability in Typo3 0.4.1/1.1/3.7.0
TYPO3 3.8.0 and earlier allows remote attackers to obtain sensitive information via a direct request to misc/phpcheck/, which invokes the phpinfo function and prints values of unspecified environment variables.
network
low complexity
typo3 CWE-200
7.5