Vulnerabilities > Typo3 > Typo3 > 4.4.6
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2012-09-04 | CVE-2012-1608 | Improper Input Validation vulnerability in Typo3 The t3lib_div::RemoveXSS API method in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and inject arbitrary web script or HTML via non printable characters. | 5.0 |
2012-09-04 | CVE-2012-1607 | Information Exposure vulnerability in Typo3 The Command Line Interface (CLI) script in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attackers to obtain the database name via a direct request. | 5.0 |
2012-09-04 | CVE-2012-1606 | Cross-Site Scripting vulnerability in Typo3 Multiple cross-site scripting (XSS) vulnerabilities in the Backend component in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allow remote authenticated backend users to inject arbitrary web script or HTML via unspecified vectors. | 3.5 |
2012-08-27 | CVE-2012-2112 | Cross-Site Scripting vulnerability in Typo3 Cross-site scripting (XSS) vulnerability in the Exception Handler in TYPO3 4.4.x before 4.4.15, 4.5.x before 4.5.15, 4.6.x before 4.6.8, and 4.7 allows remote attackers to inject arbitrary web script or HTML via exception messages. | 4.3 |