First published: Mon Mar 15 2010(Updated: )
Cross-site scripting (XSS) vulnerability in the Twitter Search (twittersearch) extension before 0.1.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
thomas loeffler twittersearch | <=0.1.0 | |
thomas loeffler twittersearch | =0.0.1 | |
thomas loeffler twittersearch | =0.0.2 | |
TYPO3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4705 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2009-4705, upgrade the Twitter Search extension to version 0.1.1 or later.
CVE-2009-4705 allows remote attackers to inject arbitrary web scripts or HTML into web pages viewed by users.
CVE-2009-4705 affects versions of Twitter Search before 0.1.1, including versions 0.0.1 and 0.0.2.
No, the vulnerability specifically affects the Twitter Search extension for TYPO3 and does not impact TYPO3 itself.