First published: Fri Aug 16 2013(Updated: )
SQL injection vulnerability in the Browser - TYPO3 without PHP (browser) extension before 4.5.5 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
die-netzmacher Browser | <=4.5.2 | |
die-netzmacher Browser | =4.5.0 | |
TYPO3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5306 is classified as a medium severity vulnerability due to its potential for SQL injection and remote code execution.
To mitigate CVE-2013-5306, upgrade the Browser - TYPO3 extension to version 4.5.5 or later.
CVE-2013-5306 allows attackers to execute arbitrary SQL commands through SQL injection vulnerability.
CVE-2013-5306 affects Browser - TYPO3 versions before 4.5.5, including 4.5.0 and up to 4.5.2.
No, the TYPO3 core itself is not vulnerable according to CVE-2013-5306; the vulnerability is related specifically to the Browser - TYPO3 extension.