CVE-2010-0340: SQL Injection
Published Jan 15, 2010
·Updated
SQL injection vulnerability in the MJS Event Pro (mjseventpro) extension 0.2.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
4 affected components
Typo3 mjseventpro<=0.2.1
Typo3 TYPO3
All of the following
Typo3 mjseventpro<=0.2.1
Typo3 TYPO3
Event History
Jan 15, 2010
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
07:30 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-0340?
CVE-2010-0340 has a high severity rating due to its potential for remote SQL injection attacks.
2
How do I fix CVE-2010-0340?
To fix CVE-2010-0340, upgrade the MJS Event Pro extension to version 0.2.2 or later.
3
What types of systems are affected by CVE-2010-0340?
CVE-2010-0340 affects TYPO3 systems that are using the MJS Event Pro extension version 0.2.1 and earlier.
4
Can CVE-2010-0340 allow attackers to compromise my database?
Yes, CVE-2010-0340 allows attackers to execute arbitrary SQL commands, potentially compromising the database.
5
Is there a known exploit for CVE-2010-0340?
While there may not be widely reported exploits, the vulnerability itself poses significant risk for exploitation if left unpatched.