Title: Share Your Car (cc20) Extension for TYPO3 Unspecified SQL Injection
Info
Disclosure
Feb 23, 2012
Discovery
Unknown
Dates
Exploit
Unknown
Solution
Unknown
Description
Share Your Car (cc20) Extension for TYPO3 contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the program not properly sanitizing certain unspecified user-supplied input before use in SQL queries. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Solution Unknown
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
OSVDB:
Web Related
Solution
OSVDB is not aware of a solution for this vulnerability.