PT-2009-5908 · Typo3 · Typo3

Christian Weiske

·

Publicado

2009-11-02

·

Atualizado

2022-05-02

·

CVE-2009-3635

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions TYPO3 versions 4.0.13 and earlier TYPO3 versions 4.1.x before 4.1.13 TYPO3 versions 4.2.x before 4.2.10 TYPO3 versions 4.3.x before 4.3beta2
Description The issue allows remote attackers to gain access by using only the password's md5 hash as a credential. This is related to the Install Tool subcomponent.
Recommendations For versions 4.0.13 and earlier, update to a version later than 4.0.13. For versions 4.1.x before 4.1.13, update to version 4.1.13 or later. For versions 4.2.x before 4.2.10, update to version 4.2.10 or later. For versions 4.3.x before 4.3beta2, update to version 4.3beta2 or later.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-3635
DSA-1926-1
GHSA-HWRC-W5GG-F335

Produtos afetados

Typo3