CVE-2012-1608
published 2012-09-04CVE-2012-1608: The t3lib_div::RemoveXSS API method in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attackers to bypass…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
2.30%
81.2th percentile
The t3lib_div::RemoveXSS API method in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and inject arbitrary web script or HTML via non printable characters.
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| typo3 | cms | >= 4.4.0 < 4.4.14 | 4.4.14 |
| typo3 | cms | >= 4.5.0 < 4.5.14 | 4.5.14 |
| typo3 | cms | >= 4.6.0 < 4.6.7 | 4.6.7 |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
| typo3 | typo3 | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Typo3 API XSS Vulnerabilities
ghsa·2022-05-17
CVE-2012-1608 [MEDIUM] CWE-20 Typo3 API XSS Vulnerabilities
Typo3 API XSS Vulnerabilities
The `t3lib_div::RemoveXSS` API method in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and inject arbitrary web script or HTML via non printable characters.
OSV
Typo3 API XSS Vulnerabilities
osv·2022-05-17
CVE-2012-1608 [MEDIUM] Typo3 API XSS Vulnerabilities
Typo3 API XSS Vulnerabilities
The `t3lib_div::RemoveXSS` API method in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and inject arbitrary web script or HTML via non printable characters.
OSV
CVE-2012-1608: The t3lib_div::RemoveXSS API method in TYPO3 4
osv·2012-09-04·CVSS 5.0
CVE-2012-1608 [MEDIUM] CVE-2012-1608: The t3lib_div::RemoveXSS API method in TYPO3 4
The t3lib_div::RemoveXSS API method in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and inject arbitrary web script or HTML via non printable characters.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/48647http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2012-001/http://www.debian.org/security/2012/dsa-2445http://www.openwall.com/lists/oss-security/2012/03/30/4http://www.osvdb.org/80762http://www.securityfocus.com/bid/52771http://secunia.com/advisories/48647http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2012-001/http://www.debian.org/security/2012/dsa-2445http://www.openwall.com/lists/oss-security/2012/03/30/4http://www.osvdb.org/80762http://www.securityfocus.com/bid/52771
2012-09-04
Published