{"containers":{"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-12-16T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in the FORM content object in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"70122","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/70122"},{"tags":["x_refsource_CONFIRM"],"url":"http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-sa-2010-022/"},{"name":"45470","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/45470"},{"name":"35770","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/35770"},{"name":"[oss-security] 20120512 Re: CVE-request: TYPO3 TYPO3-SA-2010-022 still without  CVE","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2012/05/12/5"},{"name":"[oss-security] 20110113 CVE requests: ftpls, xdigger, lbreakout2, calibre, typo3","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2011/01/13/2"},{"name":"[oss-security] 20120510  Re: CVE-request: TYPO3 TYPO3-SA-2010-022 still without  CVE","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2012/05/11/3"},{"name":"typo3-form-xss(64179)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64179"},{"name":"[oss-security] 20120511 CVE-request: TYPO3 TYPO3-SA-2010-022 still without  CVE","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2012/05/10/7"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2010-5098","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in the FORM content object in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"70122","refsource":"OSVDB","url":"http://www.osvdb.org/70122"},{"name":"http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-sa-2010-022/","refsource":"CONFIRM","url":"http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-sa-2010-022/"},{"name":"45470","refsource":"BID","url":"http://www.securityfocus.com/bid/45470"},{"name":"35770","refsource":"SECUNIA","url":"http://secunia.com/advisories/35770"},{"name":"[oss-security] 20120512 Re: CVE-request: TYPO3 TYPO3-SA-2010-022 still without  CVE","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2012/05/12/5"},{"name":"[oss-security] 20110113 CVE requests: ftpls, xdigger, lbreakout2, calibre, typo3","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2011/01/13/2"},{"name":"[oss-security] 20120510  Re: CVE-request: TYPO3 TYPO3-SA-2010-022 still without  CVE","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2012/05/11/3"},{"name":"typo3-form-xss(64179)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64179"},{"name":"[oss-security] 20120511 CVE-request: TYPO3 TYPO3-SA-2010-022 still without  CVE","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2012/05/10/7"}]}}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-07T04:09:38.866Z"},"title":"CVE Program Container","references":[{"name":"70122","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/70122"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-sa-2010-022/"},{"name":"45470","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/45470"},{"name":"35770","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/35770"},{"name":"[oss-security] 20120512 Re: CVE-request: TYPO3 TYPO3-SA-2010-022 still without  CVE","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2012/05/12/5"},{"name":"[oss-security] 20110113 CVE requests: ftpls, xdigger, lbreakout2, calibre, typo3","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2011/01/13/2"},{"name":"[oss-security] 20120510  Re: CVE-request: TYPO3 TYPO3-SA-2010-022 still without  CVE","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2012/05/11/3"},{"name":"typo3-form-xss(64179)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64179"},{"name":"[oss-security] 20120511 CVE-request: TYPO3 TYPO3-SA-2010-022 still without  CVE","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2012/05/10/7"}]}]},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2010-5098","datePublished":"2012-05-21T20:00:00.000Z","dateReserved":"2012-04-30T00:00:00.000Z","dateUpdated":"2024-08-07T04:09:38.866Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}