MidnightBSD

Advisories for nadine_schwingler

CVE-2010-4956 MEDIUM

Cross-site scripting (XSS) vulnerability in the Questionnaire (ke_questionnaire) extension before 2.2.3 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
nadine_schwingler ke_questionnaire 1.2.1
nadine_schwingler ke_questionnaire 2.0.0
nadine_schwingler ke_questionnaire *
CVE-2010-4957 HIGH

SQL injection vulnerability in the Questionnaire (ke_questionnaire) extension before 2.2.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
nadine_schwingler ke_questionnaire 1.2.1
nadine_schwingler ke_questionnaire 2.0.0
nadine_schwingler ke_questionnaire *