CVE-2010-0342: SQL Injection
Published Jan 15, 2010
·Updated
SQL injection vulnerability in the Reports for Job (jobreports) extension 0.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
4 affected components
Typo3 Job Reports<=0.1.0
Typo3 TYPO3
All of the following
Typo3 Job Reports<=0.1.0
Typo3 TYPO3
Event History
Jan 15, 2010
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
07:30 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·07:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-0342?
CVE-2010-0342 is classified as a critical vulnerability due to the potential for remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2010-0342?
To fix CVE-2010-0342, you should upgrade the Reports for Job extension to version 0.2.0 or later.
3
What software is affected by CVE-2010-0342?
CVE-2010-0342 affects TYPO3 versions running Reports for Job extension 0.1.0 and earlier.
4
Can CVE-2010-0342 be exploited remotely?
Yes, CVE-2010-0342 can be exploited remotely by attackers through unspecified vectors.
5
What kind of attacks are possible with CVE-2010-0342?
CVE-2010-0342 allows for SQL injection attacks that can lead to executing arbitrary SQL commands against the database.