Publish Advisories

GHSA-fr34-mx6j-vpxh
GHSA-m4hw-r893-xh4g
GHSA-q68v-vcjg-r3vp
GHSA-fr34-mx6j-vpxh
GHSA-m4hw-r893-xh4g
GHSA-q68v-vcjg-r3vp
This commit is contained in:
advisory-database[bot]
2025-04-12 03:03:30 +00:00
parent 391c3ae326
commit bfe61350df
6 changed files with 289 additions and 165 deletions
@@ -0,0 +1,77 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fr34-mx6j-vpxh",
"modified": "2025-04-12T03:03:02Z",
"published": "2022-05-17T05:20:42Z",
"aliases": [
"CVE-2011-4932"
],
"summary": "ImpressPages CMS eval injection vulnerability",
"details": "Eval injection vulnerability in `ip_cms/modules/standard/content_management/actions.php` in ImpressPages CMS 1.0.12 and possibly other versons before 1.0.13 allows remote attackers to execute arbitrary code via the `cm_group` parameter.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U"
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "impresspages/impresspages"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "1.0.13"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2011-4932"
},
{
"type": "PACKAGE",
"url": "https://github.com/impresspages/ImpressPages"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20120726055617/http://www.securityfocus.com/bid/49798"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20120726081336/http://www.impresspages.org/news/impresspages-1-0-13-security-release"
},
{
"type": "WEB",
"url": "http://seclists.org/bugtraq/2011/Sep/156"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2012/01/15/9"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2012/01/18/12"
}
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2025-04-12T03:03:02Z",
"nvd_published_at": "2012-10-06T21:55:00Z"
}
}
@@ -0,0 +1,106 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m4hw-r893-xh4g",
"modified": "2025-04-12T03:01:43Z",
"published": "2022-05-17T01:43:58Z",
"aliases": [
"CVE-2012-3527"
],
"summary": "TYPO3 allows remote authenticated backend users to unserialize arbitrary objects",
"details": "view_help.php in the backend help system in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote authenticated backend users to unserialize arbitrary objects and possibly execute arbitrary PHP code via an unspecified parameter, related to a \"missing signature (HMAC).\"",
"severity": [],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "typo3/cms"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "4.5.0"
},
{
"fixed": "4.5.19"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "typo3/cms"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "4.6.0"
},
{
"fixed": "4.6.12"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "typo3/cms"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "4.7.0"
},
{
"fixed": "4.7.4"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2012-3527"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/77791"
},
{
"type": "PACKAGE",
"url": "https://github.com/TYPO3/typo3"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20120817233148/http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2012-004"
},
{
"type": "WEB",
"url": "http://www.debian.org/security/2012/dsa-2537"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2012/08/22/8"
}
],
"database_specific": {
"cwe_ids": [
"CWE-502"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2025-04-12T03:01:43Z",
"nvd_published_at": "2012-09-05T23:55:00Z"
}
}
@@ -0,0 +1,106 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q68v-vcjg-r3vp",
"modified": "2025-04-12T03:00:57Z",
"published": "2022-05-17T05:23:54Z",
"aliases": [
"CVE-2012-1607"
],
"summary": "TYPO3 allows remote attackers to obtain the database name via a direct request",
"details": "The Command Line Interface (CLI) script in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attackers to obtain the database name via a direct request.",
"severity": [],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "typo3/cms"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "4.4.0"
},
{
"last_affected": "4.4.13"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "typo3/cms"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "4.5.0"
},
{
"last_affected": "4.5.13"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "typo3/cms"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "4.6.0"
},
{
"last_affected": "4.6.6"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2012-1607"
},
{
"type": "PACKAGE",
"url": "https://github.com/TYPO3/typo3"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20120426034517/http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2012-001"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20120527123559/http://www.securityfocus.com/bid/52771"
},
{
"type": "WEB",
"url": "http://www.debian.org/security/2012/dsa-2445"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2012/03/30/4"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2025-04-12T03:00:57Z",
"nvd_published_at": "2012-09-04T20:55:00Z"
}
}
@@ -1,59 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fr34-mx6j-vpxh",
"modified": "2025-04-11T04:03:27Z",
"published": "2022-05-17T05:20:42Z",
"aliases": [
"CVE-2011-4932"
],
"details": "Eval injection vulnerability in ip_cms/modules/standard/content_management/actions.php in ImpressPages CMS 1.0.12 and possibly other versons before 1.0.13 allows remote attackers to execute arbitrary code via the cm_group parameter.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2011-4932"
},
{
"type": "WEB",
"url": "http://archives.neohapsis.com/archives/bugtraq/2012-01/0029.html"
},
{
"type": "WEB",
"url": "http://seclists.org/bugtraq/2011/Sep/156"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/46193"
},
{
"type": "WEB",
"url": "http://www.impresspages.org/news/impresspages-1-0-13-security-release"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2012/01/15/9"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2012/01/18/12"
},
{
"type": "WEB",
"url": "http://www.osvdb.org/75783"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/49798"
}
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2012-10-06T21:55:00Z"
}
}
@@ -1,51 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m4hw-r893-xh4g",
"modified": "2025-04-11T04:01:49Z",
"published": "2022-05-17T01:43:58Z",
"aliases": [
"CVE-2012-3527"
],
"details": "view_help.php in the backend help system in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote authenticated backend users to unserialize arbitrary objects and possibly execute arbitrary PHP code via an unspecified parameter, related to a \"missing signature (HMAC).\"",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2012-3527"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/77791"
},
{
"type": "WEB",
"url": "http://osvdb.org/84773"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/50287"
},
{
"type": "WEB",
"url": "http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2012-004"
},
{
"type": "WEB",
"url": "http://www.debian.org/security/2012/dsa-2537"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2012/08/22/8"
}
],
"database_specific": {
"cwe_ids": [
"CWE-502"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2012-09-05T23:55:00Z"
}
}
@@ -1,55 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q68v-vcjg-r3vp",
"modified": "2025-04-11T04:01:47Z",
"published": "2022-05-17T05:23:54Z",
"aliases": [
"CVE-2012-1607"
],
"details": "The Command Line Interface (CLI) script in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attackers to obtain the database name via a direct request.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2012-1607"
},
{
"type": "WEB",
"url": "http://osvdb.org/80761"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/48622"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/48647"
},
{
"type": "WEB",
"url": "http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2012-001"
},
{
"type": "WEB",
"url": "http://www.debian.org/security/2012/dsa-2445"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2012/03/30/4"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/52771"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2012-09-04T20:55:00Z"
}
}