NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 39841 | CVE-2013-4193 | typeswidget.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly enforce the immutable setting on unspecified content edit forms, which allows remote attackers to hide fields on the forms via a crafted URL. | 2 | 4.3 | Medium | 2017-01-18 | 2014-03-11 | View | |
| 4694 | CVE-2008-4905 | Typo 5.1.3 and earlier uses a hard-coded salt for calculating password hashes, which makes it easier for attackers to guess passwords via a brute force attack. | 2 | 5 | Medium | 2017-01-03 | 2009-01-29 | View | |
| 59066 | CVE-2006-0327 | TYPO3 3.7.1 allows remote attackers to obtain sensitive information via a direct request to (1) thumbs.php, (2) showpic.php, or (3) tables.php, which causes them to incorrectly define a variable and reveal the path in an error message when a require function call fails. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 70464 | CVE-2005-4875 | TYPO3 3.8.0 and earlier allows remote attackers to obtain sensitive information via a direct request to misc/phpcheck/, which invokes the phpinfo function and prints values of unspecified environment variables. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
| 2615 | CVE-2008-2717 | TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which allows remote attackers to bypass security restrictions and upload configuration files such as .htaccess, or conduct file upload attacks using multiple extensions. | 2 | 6.5 | Medium | 2017-07-18 | 2017-07-11 | View |
Page 15231 of 17672, showing 5 records out of 88360 total, starting on record 76151, ending on 76155