SQL injection vulnerability in the Backend History module in TYPO3 4.5.x before 4.5.21, 4.6.x before 4.6.14, and 4.7.x before 4.7.6 allows remote authenticated backend users to execute arbitrary SQL commands via unspecified vectors.
https://exchange.xforce.ibmcloud.com/vulnerabilities/79964
http://www.openwall.com/lists/oss-security/2013/06/19/4
http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2012-005/