TYPO3 Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2007-6381
SQL injection vulnerability in the indexed_search system extension in TYPO3 3.x 4.0 through 4.0.7 and 4.1 through 4.1.3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.