PT-2012-1930 · Typo3 · Typo3

Björn Pedersen

+1

·

Publicado

2012-02-18

·

Atualizado

2012-02-29

·

CVE-2011-4614

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions TYPO3 versions 4.5.x through 4.5.8 TYPO3 versions 4.6.x through 4.6.1 TYPO3 development versions of 4.7
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the BACK PATH parameter. This is a result of a PHP remote file inclusion vulnerability in the workspaces system extension, specifically in Classes/Controller/AbstractController.php.
Recommendations For TYPO3 versions 4.5.x through 4.5.8, update to version 4.5.9 or later. For TYPO3 versions 4.6.x through 4.6.1, update to version 4.6.2 or later. For TYPO3 development versions of 4.7, consider avoiding the use of the BACK PATH parameter until a fixed version is available. As a temporary workaround, consider restricting access to the affected AbstractController.php file in the workspaces system extension.

Exploit

Correção

RCE

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-4614

Produtos afetados

Typo3