PT-2014-5621 · Typo3+1 · Typo3+1

Helmut Hummel

+1

·

Publicado

2014-06-03

·

Atualizado

2022-05-14

·

CVE-2014-3941

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions TYPO3 versions 4.5.0 through 4.5.33 TYPO3 versions 4.7.0 through 4.7.18 TYPO3 versions 6.0.0 through 6.0.13 TYPO3 versions 6.1.0 through 6.1.8 TYPO3 versions 6.2.0 through 6.2.2
Description The issue allows remote attackers to have an unspecified impact via a crafted HTTP Host header, related to "Host Spoofing."
Recommendations For TYPO3 versions 4.5.0 through 4.5.33, update to version 4.5.34 or later. For TYPO3 versions 4.7.0 through 4.7.18, update to version 4.7.19 or later. For TYPO3 versions 6.0.0 through 6.0.13, update to version 6.0.14 or later. For TYPO3 versions 6.1.0 through 6.1.8, update to version 6.1.9 or later. For TYPO3 versions 6.2.0 through 6.2.2, update to version 6.2.3 or later.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-3941
DSA-2942-1
GHSA-594H-CX6W-P4JF
GHSA-M2JH-FXW4-GPHM
OPENSUSE-SU-2016_2025-1

Produtos afetados

Suse
Typo3