1
Candidate: CVE-2012-3528
4
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3528
5
http://typo3.org/support/teams-security-security-bulletins/security-bulletins-single-view/article/several-vulnerabilities-in-typo3-core/
7
Multiple cross-site scripting (XSS) vulnerabilities in the backend in TYPO3
8
4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allow
9
remote authenticated backend users to inject arbitrary web script or HTML
10
via unspecified vectors.
14
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=685011
16
Discovered-by: Pavel Vaysband, Markus Bucher, Susanne Moog, and Jan Bednarik
20
upstream_typo3-src: released (4.5.19+dfsg1-1)
21
hardy_typo3-src: ignored (reached end-of-life)
22
lucid_typo3-src: ignored (reached end-of-life)
23
natty_typo3-src: released (4.3.9+dfsg1-1+squeeze5build0.11.04.1)
24
oneiric_typo3-src: ignored (reached end-of-life)
25
precise_typo3-src: ignored (reached end-of-life)
26
precise/esm_typo3-src: DNE (precise was needed)
27
quantal_typo3-src: not-affected (4.5.19+dfsg1-1)
28
raring_typo3-src: not-affected (4.5.19+dfsg1-1)
29
saucy_typo3-src: not-affected (4.5.19+dfsg1-1)
30
trusty_typo3-src: not-affected (4.5.19+dfsg1-1)
31
utopic_typo3-src: not-affected (4.5.19+dfsg1-1)
32
vivid_typo3-src: not-affected (4.5.19+dfsg1-1)
33
vivid/stable-phone-overlay_typo3-src: DNE
34
vivid/ubuntu-core_typo3-src: DNE
37
yakkety_typo3-src: DNE