PT-2012-1344 · Typo3 · Typo3

Kurt Seifried

·

Publicado

2012-05-21

·

Atualizado

2022-05-17

·

CVE-2010-5101

CVSS v4.0

4.6

Média

VetorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U
Name of the Vulnerable Software and Affected Versions TYPO3 versions 4.2.x through 4.2.15 TYPO3 versions 4.3.x through 4.3.8 TYPO3 versions 4.4.x through 4.4.4
Description A directory traversal issue exists in the TypoScript setup, allowing remote authenticated administrators to read arbitrary files. This is related to the file inclusion functionality.
Recommendations For TYPO3 versions 4.2.x through 4.2.15, update to version 4.2.16 or later. For TYPO3 versions 4.3.x through 4.3.8, update to version 4.3.9 or later. For TYPO3 versions 4.4.x through 4.4.4, update to version 4.4.5 or later.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-5101
GHSA-RMQC-WFJM-3F66

Produtos afetados

Typo3