CVE-2012-1077: SQL Injection
Published Feb 14, 2012
·Updated
SQL injection vulnerability in the Post data records to facebook (bcpost2facebook) extension before 0.2.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
3 affected components
Manfred Egger Bc Post2facebook<=0.2.1
Manfred Egger Bc Post2facebook=0.2.0
Typo3 TYPO3
Event History
Feb 14, 2012
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-1077?
CVE-2012-1077 is a high-severity vulnerability due to its potential for SQL injection, allowing remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2012-1077?
To fix CVE-2012-1077, upgrade the bc_post2facebook extension to version 0.2.2 or later.
3
What software is affected by CVE-2012-1077?
CVE-2012-1077 affects versions 0.2.1 and earlier of the bc_post2facebook extension for TYPO3.
4
Can CVE-2012-1077 be exploited remotely?
Yes, CVE-2012-1077 can be exploited remotely, allowing attackers to execute arbitrary SQL commands.
5
What type of vulnerability is CVE-2012-1077?
CVE-2012-1077 is classified as an SQL injection vulnerability.