CVE-2009-4709

TYPO3 datamints_newsticker <0.7.2 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in the datamints Newsticker (datamints_newsticker) extension before 0.7.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/35879

Scores

EPSS 0.0101
EPSS Percentile 59.5%

Details

CWE
CWE-89
Status published
Products (9)
dirk_maiwert/datamints_newsticker 0.1.0
dirk_maiwert/datamints_newsticker 0.4.0
dirk_maiwert/datamints_newsticker 0.5.0
dirk_maiwert/datamints_newsticker 0.6.0
dirk_maiwert/datamints_newsticker 0.6.1
dirk_maiwert/datamints_newsticker 0.6.2
dirk_maiwert/datamints_newsticker 0.6.3
dirk_maiwert/datamints_newsticker 0.7.0
dirk_maiwert/datamints_newsticker < 0.7.1
Published Mar 15, 2010
Tracked Since Feb 18, 2026