First published: Mon May 21 2012(Updated: )
The escapeStrForLike method in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 does not properly escape input when the MySQL database is set to sql_mode NO_BACKSLASH_ESCAPES, which allows remote attackers to obtain sensitive information via wildcard characters in a LIKE query.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Typo3 Typo3 | =4.2.10 | |
Typo3 Typo3 | =4.3.6 | |
Typo3 Typo3 | =4.2.14 | |
Typo3 Typo3 | =4.3.5 | |
Typo3 Typo3 | =4.3.8 | |
Typo3 Typo3 | =4.2.4 | |
Typo3 Typo3 | =4.2.5 | |
Typo3 Typo3 | =4.2.15 | |
Typo3 Typo3 | =4.2.11 | |
Typo3 Typo3 | =4.2.0 | |
Typo3 Typo3 | =4.3.7 | |
Typo3 Typo3 | =4.2.8 | |
Typo3 Typo3 | =4.2.13 | |
Typo3 Typo3 | =4.2.3 | |
Typo3 Typo3 | =4.4.4 | |
Typo3 Typo3 | =4.2.1 | |
Typo3 Typo3 | =4.3.2 | |
Typo3 Typo3 | =4.4.1 | |
Typo3 Typo3 | =4.4.2 | |
Typo3 Typo3 | =4.2.12 | |
Typo3 Typo3 | =4.2.6 | |
Typo3 Typo3 | =4.3.0 | |
Typo3 Typo3 | =4.2.2 | |
Typo3 Typo3 | =4.3.3 | |
Typo3 Typo3 | =4.3.4 | |
Typo3 Typo3 | =4.3.1 | |
Typo3 Typo3 | =4.2.7 | |
Typo3 Typo3 | =4.4.3 | |
Typo3 Typo3 | =4.2.9 | |
composer/typo3/cms-core | >=4.4.0<4.4.5 | 4.4.5 |
composer/typo3/cms-core | >=4.3.0<4.3.9 | 4.3.9 |
composer/typo3/cms-core | >=4.2.0<4.2.16 | 4.2.16 |
=4.2.0 | ||
=4.2.1 | ||
=4.2.2 | ||
=4.2.3 | ||
=4.2.4 | ||
=4.2.5 | ||
=4.2.6 | ||
=4.2.7 | ||
=4.2.8 | ||
=4.2.9 | ||
=4.2.10 | ||
=4.2.11 | ||
=4.2.12 | ||
=4.2.13 | ||
=4.2.14 | ||
=4.2.15 | ||
=4.3.0 | ||
=4.3.1 | ||
=4.3.2 | ||
=4.3.3 | ||
=4.3.4 | ||
=4.3.5 | ||
=4.3.6 | ||
=4.3.7 | ||
=4.3.8 | ||
=4.4.1 | ||
=4.4.2 | ||
=4.4.3 | ||
=4.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.