Unrated severityNVD Advisory· Published Mar 15, 2010· Updated Apr 29, 2026
CVE-2009-4702
CVE-2009-4702
Description
SQL injection vulnerability in the Tour Extension (pm_tour) extension before 0.0.13 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected products
5cpe:2.3:a:markus_barchfeld:pm_tour:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:markus_barchfeld:pm_tour:*:*:*:*:*:*:*:*range: <=0.0.12
- cpe:2.3:a:markus_barchfeld:pm_tour:0.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:markus_barchfeld:pm_tour:0.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:markus_barchfeld:pm_tour:0.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:markus_barchfeld:pm_tour:0.0.8:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- typo3.org/teams/security/security-bulletins/typo3-sa-2009-010/nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.