CVE-2010-1012: SQL Injection
SQL injection vulnerability in the CleanDB (nfcleandb) extension 1.0.7 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1012?
CVE-2010-1012 has been classified as a critical SQL injection vulnerability that allows attackers to execute arbitrary SQL commands.
How do I fix CVE-2010-1012?
To fix CVE-2010-1012, upgrade the CleanDB extension to version 1.0.8 or later, which addresses the SQL injection vulnerability.
Which versions of CleanDB are affected by CVE-2010-1012?
CVE-2010-1012 affects versions of CleanDB up to and including 1.0.7.
Who can exploit CVE-2010-1012?
CVE-2010-1012 can be exploited remotely by attackers with the ability to send crafted requests to the CleanDB extension.
What impact can CVE-2010-1012 have on TYPO3 installations?
Exploiting CVE-2010-1012 can lead to unauthorized access to database information, data manipulation, or complete system compromise.