Arbitrary SQL Command Execution in TYPO3 Commenting System Backend Module

Arbitrary SQL Command Execution in TYPO3 Commenting System Backend Module

CVE-2010-4887 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

SQL injection vulnerability in the Commenting system Backend Module (commentsbe) extension 0.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Learn more about our Web Application Penetration Testing UK.