CVE-2009-4396: SQL Injection
SQL injection vulnerability in the Diocese of Portsmouth Resources Database (pdresources) extension 0.1.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4396?
CVE-2009-4396 is considered a critical severity vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2009-4396?
To fix CVE-2009-4396, upgrade the Diocese of Portsmouth Resources Database extension to a version later than 0.1.1.
Who is affected by CVE-2009-4396?
CVE-2009-4396 affects users of the Diocese of Portsmouth Resources Database extension version 0.1.1 and earlier on TYPO3.
What are the potential impacts of CVE-2009-4396?
The potential impacts of CVE-2009-4396 include unauthorized access to the database and the ability to manipulate or extract sensitive data.
Is there a workaround for CVE-2009-4396?
There are no confirmed workarounds for CVE-2009-4396; the recommended action is to update to a patched version.