CVE-2012-3527
Summary
| CVE | CVE-2012-3527 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-09-05 23:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | view_help.php in the backend help system in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote authenticated backend users to unserialize arbitrary objects and possibly execute arbitrary PHP code via an unspecified parameter, related to a "missing signature (HMAC)." |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:H/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - Re: CVE request: Typo3 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List |
| Debian -- Security Information -- DSA-2537-1 typo3-src | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| osvdb.org/84773 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | Broken Link |
| Several Vulnerabilities in TYPO3 Core - TYPO3 - The Enterprise Open Source CMS | af854a3a-2127-422b-91ae-364da2661108 | typo3.org | Vendor Advisory |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Not Applicable |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.