First published: Wed Jan 28 2009(Updated: )
Cross-site scripting (XSS) vulnerability in the freeCap CAPTCHA (sr_freecap) extension before 1.0.4 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TYPO3 freeCap CAPTCHA extension | <=1.0.3 | |
TYPO3 freeCap CAPTCHA extension | =1.0.0 | |
TYPO3 freeCap CAPTCHA extension | =1.0.1 | |
TYPO3 freeCap CAPTCHA extension | =1.0.2 | |
TYPO3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5995 is classified as a medium severity vulnerability due to its potential for Cross-site scripting (XSS) attacks.
To fix CVE-2008-5995, upgrade the freeCap CAPTCHA extension to version 1.0.4 or later.
CVE-2008-5995 allows remote attackers to inject arbitrary web scripts or HTML into the application.
CVE-2008-5995 affects versions of the freeCap CAPTCHA extension prior to 1.0.4, including versions 1.0.0 to 1.0.3.
Any users of the TYPO3 freeCap CAPTCHA extension prior to version 1.0.4 are impacted by CVE-2008-5995.