Arbitrary SQL Command Execution in TYPO3 Flat Manager Extension

Arbitrary SQL Command Execution in TYPO3 Flat Manager Extension

CVE-2014-6233 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

SQL injection vulnerability in the Flat Manager (flatmgr) extension before 2.7.10 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Learn more about our Web Application Penetration Testing UK.