Arbitrary SQL Command Execution in sofortueberweisung2commerce Extension

Arbitrary SQL Command Execution in sofortueberweisung2commerce Extension

CVE-2013-4681 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

SQL injection vulnerability in the sofortueberweisung2commerce extension before 2.0.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Learn more about our Web Application Penetration Testing UK.