First published: Tue Mar 02 2010(Updated: )
Cross-site scripting (XSS) vulnerability in the T3BLOG extension 0.6.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Snowflake | <=0.6.2 | |
Snowflake | =0.5.0 | |
Snowflake | =0.6.0 | |
Snowflake | =0.6.1 | |
TYPO3 | ||
All of | ||
Any of | ||
Snowflake | <=0.6.2 | |
Snowflake | =0.5.0 | |
Snowflake | =0.6.0 | |
Snowflake | =0.6.1 | |
TYPO3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0797 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
To fix CVE-2010-0797, update the T3BLOG extension to version 0.6.3 or later.
CVE-2010-0797 affects T3BLOG versions 0.6.2 and earlier, including version 0.5.0, 0.6.0, and 0.6.1.
Any remote attacker can exploit CVE-2010-0797 to inject arbitrary web scripts or HTML.
The impact of CVE-2010-0797 allows attackers to perform cross-site scripting attacks, potentially stealing user data or compromising web sessions.