Vulnerabilities > Typo3 > Typo3 > 4.1.8

DATE CVE VULNERABILITY TITLE RISK
2009-03-05 CVE-2009-0816 Cross-Site Scripting vulnerability in Typo3
Multiple cross-site scripting (XSS) vulnerabilities in the backend user interface in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 before 4.2.6, and 4.3alpha1 allow remote attackers to inject arbitrary web script or HTML via unspecified fields.
network
typo3 CWE-79
4.3
2009-03-05 CVE-2009-0815 Information Exposure vulnerability in Typo3
The jumpUrl mechanism in class.tslib_fe.php in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 before 4.2.6, and 4.3alpha1 leaks a hash secret (juHash) in an error message, which allows remote attackers to read arbitrary files by including the hash in a request.
network
low complexity
typo3 CWE-200
5.0