CVE-2008-5609

Commerce extension <0.9.6 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in the Commerce extension 0.9.6 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

References (3)

Core 3
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2870

Scores

EPSS 0.0041
EPSS Percentile 61.7%

Details

CWE
CWE-89
Status published
Products (5)
typo3/commerce_extension 0.8.32
typo3/commerce_extension 0.8.35
typo3/commerce_extension 0.9.0
typo3/commerce_extension 0.9.5
typo3/commerce_extension < 0.9.6
Published Dec 17, 2008
Tracked Since Feb 18, 2026