SQL injection vulnerability in the Branchenbuch (aka Yellow Pages o (mhbranchenbuch) extension 0.8.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Cross-site scripting (XSS) vulnerability in the Branchenbuch (aka Yellow Pages or mhbranchenbuch) extension before 0.9.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.