CVE-2012-1075: SQL Injection
Published Feb 14, 2012
·Updated
SQL injection vulnerability in the Documents download (rtgfiles) extension before 1.5.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
6 affected components
Robert Gonda Rtg Files<=1.5.1
Robert Gonda Rtg Files=1.4.7
Robert Gonda Rtg Files=1.4.9
Robert Gonda Rtg Files=1.4.10
Robert Gonda Rtg Files=1.5.0
Typo3 TYPO3
Event History
Feb 14, 2012
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-1075?
CVE-2012-1075 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2012-1075?
To fix CVE-2012-1075, upgrade the Documents download (rtg_files) extension to version 1.5.2 or later.
3
Who is affected by CVE-2012-1075?
CVE-2012-1075 affects users of the Documents download (rtg_files) extension versions 1.5.1 and earlier.
4
What types of attacks can be executed through CVE-2012-1075?
Remote attackers can execute arbitrary SQL commands through the CVE-2012-1075 vulnerability.
5
Which software components are involved in CVE-2012-1075?
CVE-2012-1075 involves the Documents download (rtg_files) extension for the TYPO3 content management system.