PT-2014-2767 · Typo3 · Typo3

Publicado

2014-05-20

·

Atualizado

2022-05-17

·

CVE-2013-4250

CVSS v4.0

8.7

Alta

VetorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions TYPO3 versions 6.0.0 through 6.0.7 TYPO3 versions 6.1.0 through 6.1.2
Description The issue concerns the file upload component and the File Abstraction Layer (FAL) in TYPO3, which do not properly check file extensions. This allows remote authenticated editors to execute arbitrary PHP code by uploading a .php file.
Recommendations For TYPO3 versions 6.0.0 through 6.0.7, update to version 6.0.8 or later. For TYPO3 versions 6.1.0 through 6.1.2, update to version 6.1.3 or later.

Correção

Unrestricted File Upload

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-4250
GHSA-54JJ-PXX2-PV8H

Produtos afetados

Typo3