CVE-2009-4711: SQL Injection
Published Mar 15, 2010
·Updated
SQL injection vulnerability in the CoolURI (cooluri) extension before 1.0.16 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2008-6686.
Affected Software
12 affected components
Jan Bednarik Cooluri<=1.0.15
Jan Bednarik Cooluri=1.0.11
Jan Bednarik Cooluri=1.0.12
Jan Bednarik Cooluri=1.0.13
Jan Bednarik Cooluri=1.0.14
Typo3 TYPO3
All of the following
Any of the following
Jan Bednarik Cooluri<=1.0.15
Jan Bednarik Cooluri=1.0.11
Jan Bednarik Cooluri=1.0.12
Jan Bednarik Cooluri=1.0.13
Jan Bednarik Cooluri=1.0.14
Typo3 TYPO3
Remediation
Event History
Mar 15, 2010
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
09:30 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·09:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-4711?
CVE-2009-4711 has a moderate severity level due to the potential for SQL injection attacks.
2
How do I fix CVE-2009-4711?
To fix CVE-2009-4711, upgrade the CoolURI extension to version 1.0.16 or later.
3
Which versions of CoolURI are affected by CVE-2009-4711?
CVE-2009-4711 affects all versions of the CoolURI extension prior to 1.0.16.
4
What type of vulnerability is CVE-2009-4711?
CVE-2009-4711 is categorized as an SQL injection vulnerability.
5
Can CVE-2009-4711 impact TYPO3 installations?
Yes, CVE-2009-4711 can impact TYPO3 installations that use vulnerable versions of the CoolURI extension.