First published: Fri Mar 19 2010(Updated: )
SQL injection vulnerability in the SAV Filter Months (sav_filter_months) extension before 1.0.5 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
laurent foulloy SAV Filter Months | <=1.0.4 | |
laurent foulloy SAV Filter Months | =1.0.0 | |
laurent foulloy SAV Filter Months | =1.0.1 | |
laurent foulloy SAV Filter Months | =1.0.2 | |
laurent foulloy SAV Filter Months | =1.0.3 | |
TYPO3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1017 is considered a critical vulnerability due to its SQL injection nature, which allows attackers to execute arbitrary SQL commands.
To fix CVE-2010-1017, upgrade the SAV Filter Months extension to version 1.0.5 or later.
CVE-2010-1017 affects versions of the SAV Filter Months extension prior to 1.0.5.
CVE-2010-1017 does not affect TYPO3 itself, but rather a particular extension used with it.
If upgrading is not possible for CVE-2010-1017, consider disabling the SAV Filter Months extension until a fix can be applied.