Vulnerabilities > Typo3 > Typo3 > 4.3.6

DATE CVE VULNERABILITY TITLE RISK
2010-10-25 CVE-2010-3716 Improper Input Validation vulnerability in Typo3
The be_user_creation task in TYPO3 4.2.x before 4.2.15 and 4.3.x before 4.3.7 allows remote authenticated users to gain privileges via a crafted POST request that creates a user account with arbitrary group memberships.
network
typo3 CWE-20
6.0
2010-10-25 CVE-2010-3715 Cross-Site Scripting vulnerability in Typo3
Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the RemoveXSS function, and allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (2) the backend.
network
typo3 CWE-79
4.3
2010-10-25 CVE-2010-3714 Permissions, Privileges, and Access Controls vulnerability in Typo3
The jumpUrl (aka access tracking) implementation in tslib/class.tslib_fe.php in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 does not properly compare certain hash values during access-control decisions, which allows remote attackers to read arbitrary files via unspecified vectors.
network
typo3 CWE-264
7.1