Description
SQL injection vulnerability in the Store Locator extension before 1.2.8 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
References (3)
Core 3
Core References
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/34573
Patch x_refsource_confirm
http://typo3.org/extensions/repository/view/locator/1.2.8/
Patch, Vendor Advisory x_refsource_confirm
http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-005/
Scores
EPSS
0.0105
EPSS Percentile
60.8%
Details
CWE
CWE-89
Status
published
Products (5)
joachim_ruhs/locator
1.0.6
joachim_ruhs/locator
1.0.7
joachim_ruhs/locator
1.1.0
joachim_ruhs/locator
1.1.8
joachim_ruhs/locator
< 1.2.6
Published
Jul 22, 2010
Tracked Since
Feb 18, 2026