|
|
| |
|
| |
typo3-src: cross-site scripting
| Package(s): | typo3-src |
CVE #(s): | CVE-2012-2112
|
| Created: | April 23, 2012 |
Updated: | April 25, 2012 |
| Description: |
From the Debian advisory:
Helmut Hummel of the typo3 security team discovered that typo3, a web
content management system, is not properly sanitizing output of the
exception handler. This allows an attacker to conduct cross-site
scripting attacks if either third-party extensions are installed that do
not sanitize this output on their own or in the presence of extensions
using the extbase MVC framework which accept objects to controller actions. |
| Alerts: |
|
( Log in to post comments)
|
|
|