MidnightBSD

Advisories for typosphere

CVE-2008-4903 MEDIUM

Cross-site scripting (XSS) vulnerability in the leave comment (feedback) feature in Typo 5.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) comment[author] (Name) and (2) comment[url] (Website) parameters.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
typosphere typo *
typosphere typo 5.1.2
typosphere typo 2.6.0
typosphere typo 5.0.3
typosphere typo 2.5.7
typosphere typo 2.5.8
typosphere typo 2.5.0
typosphere typo 5.1.1
typosphere typo 2.5.3
typosphere typo 1.6.8
typosphere typo 3.99.1
typosphere typo 1.6
typosphere typo 2.0.6
typosphere typo 2.5.5
typosphere typo 2.5.2
typosphere typo 2.5.6
typosphere typo 5.0.2
typosphere typo 2.0.5
typosphere typo 3.99.3
typosphere typo 2.5.1
typosphere typo 2.0.0
typosphere typo 2.5.4
typosphere typo 5.0.3.98
typosphere typo 4.1.1
typosphere typo 3.99.0
typosphere typo 3.99.2
typosphere typo 3.99.4
typosphere typo 5.0.3.98.1
typosphere typo 5.1
typosphere typo 2.0.1
typosphere typo 4.0.0
CVE-2008-4904 MEDIUM

SQL injection vulnerability in the "Manage pages" feature (admin/pages) in Typo 5.1.3 and earlier allows remote authenticated users with "blog publisher" rights to execute arbitrary SQL commands via the search[published_at] parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
typosphere typo *
typosphere typo 5.1.2
typosphere typo 2.6.0
typosphere typo 5.0.3
typosphere typo 2.5.7
typosphere typo 2.5.8
typosphere typo 2.5.0
typosphere typo 5.1.1
typosphere typo 2.5.3
typosphere typo 1.6.8
typosphere typo 3.99.1
typosphere typo 1.6
typosphere typo 2.0.6
typosphere typo 2.5.5
typosphere typo 2.5.2
typosphere typo 2.5.6
typosphere typo 5.0.2
typosphere typo 2.0.5
typosphere typo 3.99.3
typosphere typo 2.5.1
typosphere typo 2.0.0
typosphere typo 2.5.4
typosphere typo 5.0.3.98
typosphere typo 4.1.1
typosphere typo 3.99.0
typosphere typo 3.99.2
typosphere typo 3.99.4
typosphere typo 5.0.3.98.1
typosphere typo 5.1
typosphere typo 2.0.1
typosphere typo 4.0.0
CVE-2008-4905 MEDIUM

Typo 5.1.3 and earlier uses a hard-coded salt for calculating password hashes, which makes it easier for attackers to guess passwords via a brute force attack.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 3.9 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-330,

Products Affected

Vendor Product Version
typosphere typo *