First published: Tue Jul 27 2010(Updated: )
SQL injection vulnerability in the Event Registration (event_registr) extension 1.0.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
christian ehmann Event Registr | <=1.0.0 | |
Typo3 Typo3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4968 is classified as a medium severity SQL injection vulnerability.
To mitigate CVE-2009-4968, upgrade the Event Registration extension to version 1.0.1 or later.
CVE-2009-4968 affects Event Registration extension versions 1.0.0 and earlier.
Yes, CVE-2009-4968 can allow remote attackers to execute arbitrary SQL commands.
CVE-2009-4968 can be exploited through unspecified vectors that enable SQL injection.