CVE-2009-3634: XSS
Published Nov 2, 2009
·Updated
Cross-site scripting (XSS) vulnerability in the Frontend Login Box (aka felogin) subcomponent in TYPO3 4.2.0 through 4.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
Affected Software
6 affected components
Typo3 TYPO3=4.2.4
Typo3 TYPO3=4.2.5
Typo3 TYPO3=4.2.0
Typo3 TYPO3=4.2.1
Typo3 TYPO3=4.2.6
Typo3 TYPO3=4.2.2
Remediation
Patch Available
Patch Available
Event History
Nov 2, 2009
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-3634?
CVE-2009-3634 is classified as a moderate severity vulnerability due to its cross-site scripting nature.
2
How do I fix CVE-2009-3634?
To fix CVE-2009-3634, you should upgrade TYPO3 to version 4.2.7 or later.
3
Which versions of TYPO3 are affected by CVE-2009-3634?
CVE-2009-3634 affects TYPO3 versions 4.2.0 through 4.2.6.
4
What type of vulnerability is CVE-2009-3634?
CVE-2009-3634 is a cross-site scripting (XSS) vulnerability.
5
Who can exploit CVE-2009-3634?
CVE-2009-3634 can be exploited by remote attackers to inject arbitrary web scripts or HTML.