CVE-2012-1073: XSS
Published Feb 14, 2012
·Updated
Cross-site scripting (XSS) vulnerability in the Category-System (toicategory) extension 0.6.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
2 affected components
Typo3 Toi Category<=0.6.0
Typo3 TYPO3
Event History
Feb 14, 2012
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-1073?
The severity of CVE-2012-1073 is classified as high due to the potential for remote code execution through cross-site scripting.
2
How do I fix CVE-2012-1073?
To fix CVE-2012-1073, update the toi_category extension to version 0.6.1 or later.
3
What systems are affected by CVE-2012-1073?
CVE-2012-1073 affects TYPO3 systems using the toi_category extension version 0.6.0 and earlier.
4
What type of vulnerability is CVE-2012-1073?
CVE-2012-1073 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject malicious web scripts.
5
Can CVE-2012-1073 be exploited without authentication?
Yes, CVE-2012-1073 can be exploited by remote attackers without the need for authentication.