diff --git a/advisories/github-reviewed/2022/05/GHSA-fr34-mx6j-vpxh/GHSA-fr34-mx6j-vpxh.json b/advisories/github-reviewed/2022/05/GHSA-fr34-mx6j-vpxh/GHSA-fr34-mx6j-vpxh.json new file mode 100644 index 00000000000..3ed0ca0d3b4 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-fr34-mx6j-vpxh/GHSA-fr34-mx6j-vpxh.json @@ -0,0 +1,77 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fr34-mx6j-vpxh", + "modified": "2025-04-12T03:03:02Z", + "published": "2022-05-17T05:20:42Z", + "aliases": [ + "CVE-2011-4932" + ], + "summary": "ImpressPages CMS eval injection vulnerability", + "details": "Eval injection vulnerability in `ip_cms/modules/standard/content_management/actions.php` in ImpressPages CMS 1.0.12 and possibly other versons before 1.0.13 allows remote attackers to execute arbitrary code via the `cm_group` parameter.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "impresspages/impresspages" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.0.13" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2011-4932" + }, + { + "type": "PACKAGE", + "url": "https://github.com/impresspages/ImpressPages" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20120726055617/http://www.securityfocus.com/bid/49798" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20120726081336/http://www.impresspages.org/news/impresspages-1-0-13-security-release" + }, + { + "type": "WEB", + "url": "http://seclists.org/bugtraq/2011/Sep/156" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2012/01/15/9" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2012/01/18/12" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2025-04-12T03:03:02Z", + "nvd_published_at": "2012-10-06T21:55:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-m4hw-r893-xh4g/GHSA-m4hw-r893-xh4g.json b/advisories/github-reviewed/2022/05/GHSA-m4hw-r893-xh4g/GHSA-m4hw-r893-xh4g.json new file mode 100644 index 00000000000..617cd215362 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-m4hw-r893-xh4g/GHSA-m4hw-r893-xh4g.json @@ -0,0 +1,106 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4hw-r893-xh4g", + "modified": "2025-04-12T03:01:43Z", + "published": "2022-05-17T01:43:58Z", + "aliases": [ + "CVE-2012-3527" + ], + "summary": "TYPO3 allows remote authenticated backend users to unserialize arbitrary objects", + "details": "view_help.php in the backend help system in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote authenticated backend users to unserialize arbitrary objects and possibly execute arbitrary PHP code via an unspecified parameter, related to a \"missing signature (HMAC).\"", + "severity": [], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.5.0" + }, + { + "fixed": "4.5.19" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.6.0" + }, + { + "fixed": "4.6.12" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.7.0" + }, + { + "fixed": "4.7.4" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2012-3527" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/77791" + }, + { + "type": "PACKAGE", + "url": "https://github.com/TYPO3/typo3" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20120817233148/http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2012-004" + }, + { + "type": "WEB", + "url": "http://www.debian.org/security/2012/dsa-2537" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2012/08/22/8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-04-12T03:01:43Z", + "nvd_published_at": "2012-09-05T23:55:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-q68v-vcjg-r3vp/GHSA-q68v-vcjg-r3vp.json b/advisories/github-reviewed/2022/05/GHSA-q68v-vcjg-r3vp/GHSA-q68v-vcjg-r3vp.json new file mode 100644 index 00000000000..baaa6ea8312 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-q68v-vcjg-r3vp/GHSA-q68v-vcjg-r3vp.json @@ -0,0 +1,106 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q68v-vcjg-r3vp", + "modified": "2025-04-12T03:00:57Z", + "published": "2022-05-17T05:23:54Z", + "aliases": [ + "CVE-2012-1607" + ], + "summary": "TYPO3 allows remote attackers to obtain the database name via a direct request", + "details": "The Command Line Interface (CLI) script in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attackers to obtain the database name via a direct request.", + "severity": [], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.4.0" + }, + { + "last_affected": "4.4.13" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.5.0" + }, + { + "last_affected": "4.5.13" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.6.0" + }, + { + "last_affected": "4.6.6" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2012-1607" + }, + { + "type": "PACKAGE", + "url": "https://github.com/TYPO3/typo3" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20120426034517/http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2012-001" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20120527123559/http://www.securityfocus.com/bid/52771" + }, + { + "type": "WEB", + "url": "http://www.debian.org/security/2012/dsa-2445" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2012/03/30/4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-04-12T03:00:57Z", + "nvd_published_at": "2012-09-04T20:55:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-fr34-mx6j-vpxh/GHSA-fr34-mx6j-vpxh.json b/advisories/unreviewed/2022/05/GHSA-fr34-mx6j-vpxh/GHSA-fr34-mx6j-vpxh.json deleted file mode 100644 index 299cff23b89..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-fr34-mx6j-vpxh/GHSA-fr34-mx6j-vpxh.json +++ /dev/null @@ -1,59 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-fr34-mx6j-vpxh", - "modified": "2025-04-11T04:03:27Z", - "published": "2022-05-17T05:20:42Z", - "aliases": [ - "CVE-2011-4932" - ], - "details": "Eval injection vulnerability in ip_cms/modules/standard/content_management/actions.php in ImpressPages CMS 1.0.12 and possibly other versons before 1.0.13 allows remote attackers to execute arbitrary code via the cm_group parameter.", - "severity": [], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2011-4932" - }, - { - "type": "WEB", - "url": "http://archives.neohapsis.com/archives/bugtraq/2012-01/0029.html" - }, - { - "type": "WEB", - "url": "http://seclists.org/bugtraq/2011/Sep/156" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/46193" - }, - { - "type": "WEB", - "url": "http://www.impresspages.org/news/impresspages-1-0-13-security-release" - }, - { - "type": "WEB", - "url": "http://www.openwall.com/lists/oss-security/2012/01/15/9" - }, - { - "type": "WEB", - "url": "http://www.openwall.com/lists/oss-security/2012/01/18/12" - }, - { - "type": "WEB", - "url": "http://www.osvdb.org/75783" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/bid/49798" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-94" - ], - "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2012-10-06T21:55:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-m4hw-r893-xh4g/GHSA-m4hw-r893-xh4g.json b/advisories/unreviewed/2022/05/GHSA-m4hw-r893-xh4g/GHSA-m4hw-r893-xh4g.json deleted file mode 100644 index 2b1e5052da9..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-m4hw-r893-xh4g/GHSA-m4hw-r893-xh4g.json +++ /dev/null @@ -1,51 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-m4hw-r893-xh4g", - "modified": "2025-04-11T04:01:49Z", - "published": "2022-05-17T01:43:58Z", - "aliases": [ - "CVE-2012-3527" - ], - "details": "view_help.php in the backend help system in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote authenticated backend users to unserialize arbitrary objects and possibly execute arbitrary PHP code via an unspecified parameter, related to a \"missing signature (HMAC).\"", - "severity": [], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2012-3527" - }, - { - "type": "WEB", - "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/77791" - }, - { - "type": "WEB", - "url": "http://osvdb.org/84773" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/50287" - }, - { - "type": "WEB", - "url": "http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2012-004" - }, - { - "type": "WEB", - "url": "http://www.debian.org/security/2012/dsa-2537" - }, - { - "type": "WEB", - "url": "http://www.openwall.com/lists/oss-security/2012/08/22/8" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-502" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2012-09-05T23:55:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-q68v-vcjg-r3vp/GHSA-q68v-vcjg-r3vp.json b/advisories/unreviewed/2022/05/GHSA-q68v-vcjg-r3vp/GHSA-q68v-vcjg-r3vp.json deleted file mode 100644 index 00fd98f4e4f..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-q68v-vcjg-r3vp/GHSA-q68v-vcjg-r3vp.json +++ /dev/null @@ -1,55 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-q68v-vcjg-r3vp", - "modified": "2025-04-11T04:01:47Z", - "published": "2022-05-17T05:23:54Z", - "aliases": [ - "CVE-2012-1607" - ], - "details": "The Command Line Interface (CLI) script in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attackers to obtain the database name via a direct request.", - "severity": [], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2012-1607" - }, - { - "type": "WEB", - "url": "http://osvdb.org/80761" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/48622" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/48647" - }, - { - "type": "WEB", - "url": "http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2012-001" - }, - { - "type": "WEB", - "url": "http://www.debian.org/security/2012/dsa-2445" - }, - { - "type": "WEB", - "url": "http://www.openwall.com/lists/oss-security/2012/03/30/4" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/bid/52771" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-200" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2012-09-04T20:55:00Z" - } -} \ No newline at end of file