LWN.net Logo

typo3-src: cross-site scripting

Package(s):typo3-src CVE #(s):CVE-2012-2112
Created:April 23, 2012 Updated:April 25, 2012
Description: From the Debian advisory:

Helmut Hummel of the typo3 security team discovered that typo3, a web content management system, is not properly sanitizing output of the exception handler. This allows an attacker to conduct cross-site scripting attacks if either third-party extensions are installed that do not sanitize this output on their own or in the presence of extensions using the extbase MVC framework which accept objects to controller actions.

Alerts:
Debian DSA-2455-1 2012-04-20

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds