CVE-2009-4704: Medium severity Typo3 Ws Ecard vulnerability
Published Mar 15, 2010
·Updated
Unspecified vulnerability in the Webesse E-Card (wsecard) extension 1.0.2 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown vectors.
Affected Software
4 affected components
Typo3 Ws Ecard<=1.0.2
Typo3 TYPO3
All of the following
Typo3 Ws Ecard<=1.0.2
Typo3 TYPO3
Event History
Mar 15, 2010
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
09:30 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·09:30 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-4704?
CVE-2009-4704 is considered a medium risk vulnerability due to the potential for remote attackers to access sensitive information.
2
How do I fix CVE-2009-4704?
To mitigate CVE-2009-4704, update the Webesse E-Card extension to version 1.0.3 or later.
3
Which versions of TYPO3 are affected by CVE-2009-4704?
CVE-2009-4704 affects versions of the Webesse E-Card extension up to and including 1.0.2.
4
What can attackers achieve with CVE-2009-4704?
Attackers exploiting CVE-2009-4704 can obtain sensitive information from vulnerable TYPO3 installations.
5
Is my TYPO3 installation vulnerable to CVE-2009-4704?
If you are using the Webesse E-Card extension version 1.0.2 or earlier, your TYPO3 installation is vulnerable to CVE-2009-4704.