Vulnerabilities > Typo3 > Typo3 > 4.0

DATE CVE VULNERABILITY TITLE RISK
2006-12-21 CVE-2006-6690 Remote Command Execution vulnerability in Typo3 Class.TX_RTEHTMLArea_PI1.PHP
rtehtmlarea/pi1/class.tx_rtehtmlarea_pi1.php in Typo3 4.0.0 through 4.0.3, 3.7 and 3.8 with the rtehtmlarea extension, and 4.1 beta allows remote authenticated users to execute arbitrary commands via shell metacharacters in the userUid parameter to rtehtmlarea/htmlarea/plugins/SpellChecker/spell-check-logic.php, and possibly another vector.
network
low complexity
typo3
7.5
2006-09-28 CVE-2006-5069 Cross-Site Scripting vulnerability in Typo3 Indexed Search
Cross-site scripting (XSS) vulnerability in class.tx_indexedsearch.php in the Indexed Search 2.9.0 extension for Typo3 before 4.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.
network
high complexity
typo3
2.6