CVE-2012-1071: SQL Injection
Published Feb 14, 2012
·Updated
SQL injection vulnerability in the Kitchen recipe (mvcooking) extension before 0.4.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, as exploited in the wild as of February 2012.
Affected Software
4 affected components
Mathieu Vidal Mv Cooking=0.1.0
Mathieu Vidal Mv Cooking=0.3.0
Mathieu Vidal Mv Cooking=0.4.0
Typo3 TYPO3
Event History
Feb 14, 2012
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-1071?
CVE-2012-1071 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2012-1071?
To fix CVE-2012-1071, upgrade to mv_cooking extension version 0.4.1 or later.
3
What is the impact of CVE-2012-1071 on TYPO3?
CVE-2012-1071 allows remote attackers to execute arbitrary SQL commands, potentially compromising the database.
4
Which versions of mv_cooking are vulnerable to CVE-2012-1071?
Versions 0.1.0, 0.3.0, and 0.4.0 of the mv_cooking extension are vulnerable to CVE-2012-1071.
5
Is TYPO3 itself vulnerable due to CVE-2012-1071?
No, TYPO3 itself is not vulnerable; only the mv_cooking extension versions prior to 0.4.1 are affected.