Vulnerabilities > Typo3 > Typo3 > 4.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2006-12-21 | CVE-2006-6690 | Remote Command Execution vulnerability in Typo3 Class.TX_RTEHTMLArea_PI1.PHP rtehtmlarea/pi1/class.tx_rtehtmlarea_pi1.php in Typo3 4.0.0 through 4.0.3, 3.7 and 3.8 with the rtehtmlarea extension, and 4.1 beta allows remote authenticated users to execute arbitrary commands via shell metacharacters in the userUid parameter to rtehtmlarea/htmlarea/plugins/SpellChecker/spell-check-logic.php, and possibly another vector. | 7.5 |
2006-09-28 | CVE-2006-5069 | Cross-Site Scripting vulnerability in Typo3 Indexed Search Cross-site scripting (XSS) vulnerability in class.tx_indexedsearch.php in the Indexed Search 2.9.0 extension for Typo3 before 4.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter. | 2.6 |