{"api_version":"1","generated_at":"2026-07-23T07:41:38+00:00","cve":"CVE-2010-3663","urls":{"html":"https://cve.report/CVE-2010-3663","api":"https://cve.report/api/cve/CVE-2010-3663.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-3663","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-3663"},"summary":{"title":"CVE-2010-3663","description":"TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains an insecure default value of the variable fileDenyPattern which could allow remote attackers to execute arbitrary code on the backend.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-11-04 22:15:00","updated_at":"2019-11-05 17:51:00"},"problem_types":["CWE-434"],"metrics":[],"references":[{"url":"https://security-tracker.debian.org/tracker/CVE-2010-3663","name":"https://security-tracker.debian.org/tracker/CVE-2010-3663","refsource":"MISC","tags":["Third Party Advisory"],"title":"CVE-2010-3663","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://typo3.org/security/advisory/typo3-sa-2010-012/#Arbitrary_Code_Execution","name":"https://typo3.org/security/advisory/typo3-sa-2010-012/#Arbitrary_Code_Execution","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"TYPO3-SA-2010-012: Multiple vulnerabilities in TYPO3 Core","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=590719","name":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=590719","refsource":"MISC","tags":["Mailing List","Third Party Advisory"],"title":"#590719 - TYPO3 Security Bulletin TYPO3-SA-2010-012: Multiple vulnerabilities in TYPO3 Core - Debian Bug report logs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-3663","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-3663","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"3663","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"typo3","cpe5":"typo3","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"3663","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"typo3","cpe5":"typo3","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2010-3663","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains an insecure default value of the variable fileDenyPattern which could allow remote attackers to execute arbitrary code on the backend."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://security-tracker.debian.org/tracker/CVE-2010-3663","refsource":"MISC","name":"https://security-tracker.debian.org/tracker/CVE-2010-3663"},{"refsource":"MISC","name":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=590719","url":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=590719"},{"refsource":"CONFIRM","name":"https://typo3.org/security/advisory/typo3-sa-2010-012/#Arbitrary_Code_Execution","url":"https://typo3.org/security/advisory/typo3-sa-2010-012/#Arbitrary_Code_Execution"}]}},"nvd":{"publishedDate":"2019-11-04 22:15:00","lastModifiedDate":"2019-11-05 17:51:00","problem_types":["CWE-434"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*","versionStartIncluding":"4.4.0","versionEndExcluding":"4.4.1","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*","versionStartIncluding":"4.3.0","versionEndExcluding":"4.3.4","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*","versionEndExcluding":"4.1.14","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2.0","versionEndExcluding":"4.2.13","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"3663","Ordinal":"45947","Title":"CVE-2010-3663","CVE":"CVE-2010-3663","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"3663","Ordinal":"1","NoteData":"TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains an insecure default value of the variable fileDenyPattern which could allow remote attackers to execute arbitrary code on the backend.","Type":"Description","Title":null},{"CveYear":"2010","CveId":"3663","Ordinal":"2","NoteData":"2019-11-04","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"3663","Ordinal":"3","NoteData":"2019-11-04","Type":"Other","Title":"Modified"}]}}}