CVE-2010-5104

The escapeStrForLike method in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 does not properly escape input when the MySQL database is set to sql_mode NO_BACKSLASH_ESCAPES, which allows remote attackers to obtain sensitive information via wildcard characters in a LIKE query.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 72%
VendorProductVersion
typo3typo3
4.2.0
typo3typo3
4.2.1
typo3typo3
4.2.2
typo3typo3
4.2.3
typo3typo3
4.2.4
typo3typo3
4.2.5
typo3typo3
4.2.6
typo3typo3
4.2.7
typo3typo3
4.2.8
typo3typo3
4.2.9
typo3typo3
4.2.10
typo3typo3
4.2.11
typo3typo3
4.2.12
typo3typo3
4.2.13
typo3typo3
4.2.14
typo3typo3
4.2.15
typo3typo3
4.3.0
typo3typo3
4.3.1
typo3typo3
4.3.2
typo3typo3
4.3.3
typo3typo3
4.3.4
typo3typo3
4.3.5
typo3typo3
4.3.6
typo3typo3
4.3.7
typo3typo3
4.3.8
typo3typo3
4.4.1
typo3typo3
4.4.2
typo3typo3
4.4.3
typo3typo3
4.4.4
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
typo3-src
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
not-affected
lucid
ignored
hardy
ignored