Vulnerabilities > Typo3 > Typo3 > 4.3.5
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2010-10-25 | CVE-2010-3716 | Improper Input Validation vulnerability in Typo3 The be_user_creation task in TYPO3 4.2.x before 4.2.15 and 4.3.x before 4.3.7 allows remote authenticated users to gain privileges via a crafted POST request that creates a user account with arbitrary group memberships. | 6.0 |
2010-10-25 | CVE-2010-3715 | Cross-Site Scripting vulnerability in Typo3 Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the RemoveXSS function, and allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (2) the backend. | 4.3 |
2010-10-25 | CVE-2010-3714 | Permissions, Privileges, and Access Controls vulnerability in Typo3 The jumpUrl (aka access tracking) implementation in tslib/class.tslib_fe.php in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 does not properly compare certain hash values during access-control decisions, which allows remote attackers to read arbitrary files via unspecified vectors. | 7.1 |