CVE-2012-1072: SQL Injection
SQL injection vulnerability in the Category-System (toicategory) extension 0.6.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1072?
CVE-2012-1072 is classified as a critical vulnerability due to the potential for remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2012-1072?
To fix CVE-2012-1072, upgrade the Category-System (toi_category) extension to version 0.6.1 or later.
Which versions are affected by CVE-2012-1072?
CVE-2012-1072 affects version 0.6.0 and earlier of the Category-System (toi_category) extension for TYPO3.
What kind of attacks can be executed via CVE-2012-1072?
CVE-2012-1072 allows remote attackers to execute arbitrary SQL commands, potentially compromising the database.
Is TYPO3 itself vulnerable due to CVE-2012-1072?
No, TYPO3 itself is not vulnerable; only the specific toi_category extension versions 0.6.0 and earlier are affected.