PT-2010-5630 · Typo3 · Typo3

Gregor Kopf

·

Publicado

1970-01-01

·

Atualizado

2010-10-27

·

CVE-2010-3716

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions TYPO3 versions 4.2.x through 4.2.14 TYPO3 versions 4.3.x through 4.3.6
Description The issue allows remote authenticated users to gain privileges via a crafted POST request that creates a user account with arbitrary group memberships. Multiple vulnerabilities in the TYPO3 package may lead to a breach of protected information, and exploitation can be done remotely.
Recommendations For TYPO3 versions 4.2.x through 4.2.14, update to version 4.2.15 or later. For TYPO3 versions 4.3.x through 4.3.6, update to version 4.3.7 or later.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-01425
BDU:2015-02085
CVE-2010-3716
DSA-2121-1

Produtos afetados

Typo3