Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2013-7082

Cross-site scripting (XSS) vulnerability in the errorAction method in the ActionController base class in TYPO3 Flow (formerly FLOW3) 1.1.x before 1.1.1 and 2.0.x before 2.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified input, which is returned in an error message.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 53.5%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2013-7082
  • Typo3 » Flow » Version: 1.1.0
    cpe:2.3:a:typo3:flow:1.1.0
  • Typo3 » Flow » Version: 2.0.0
    cpe:2.3:a:typo3:flow:2.0.0


Contact Us

Shodan ® - All rights reserved