First published: Fri Mar 19 2010(Updated: )
SQL injection vulnerability in the Yet another TYPO3 search engine (YATSE) extension before 0.3.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
mischa heimann YATSE | <=0.3.1 | |
mischa heimann YATSE | =0.1.0 | |
mischa heimann YATSE | =0.1.1 | |
mischa heimann YATSE | =0.2.0 | |
mischa heimann YATSE | =0.3.0 | |
TYPO3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1004 is classified as a medium-severity vulnerability due to its potential for SQL injection exploits.
To fix CVE-2010-1004, upgrade the YATSE extension to version 0.3.2 or later.
CVE-2010-1004 affects users of the YATSE extension for TYPO3 versions up to and including 0.3.1.
CVE-2010-1004 is an SQL injection vulnerability allowing remote attackers to execute arbitrary SQL commands.
CVE-2010-1004 was disclosed in 2010, specifically noted for its impact on earlier versions of the YATSE extension.