TYPO3 Cross-Site Scripting Vulnerability and File Upload Vulnerability
BID:29657
Info
TYPO3 Cross-Site Scripting Vulnerability and File Upload Vulnerability
| Bugtraq ID: | 29657 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2717 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 11 2008 12:00AM |
| Updated: | May 07 2015 05:28PM |
| Credit: | Michiel Roos, Marcus Krause, Christian Seifert, Jeroen van Iddekinge, and Arnd Messer |
| Vulnerable: |
Typo3 Typo3 4.2 Typo3 Typo3 4.1.6 Typo3 Typo3 4.1.4 Typo3 Typo3 4.1 Typo3 Typo3 4.0.8 Typo3 Typo3 4.0.5 Typo3 Typo3 4.0.4 Typo3 Typo3 4.0.3 Typo3 Typo3 4.0.2 Typo3 Typo3 4.0.1 Typo3 Typo3 3.7 .0 Typo3 Typo3 3.6.2 Typo3 Typo3 3.5 b5 Typo3 Typo3 3.5 .0 Typo3 Typo3 4.1beta Typo3 Typo3 4.1 RC1 Typo3 Typo3 4.0 Typo3 Typo3 3.8 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
Typo3 Typo3 4.2.1 Typo3 Typo3 4.1.7 Typo3 Typo3 4.0.9 |
Discussion
TYPO3 Cross-Site Scripting Vulnerability and File Upload Vulnerability
TYPO3 is prone to a cross-site scripting vulnerability and a file-upload vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage the cross-site scripting issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks. The attacker can exploit the file-upload issue to execute arbitrary code in the context of the webserver.
TYPO3 3.x, 4.0 to 4.0.8, 4.1 to 4.1.6, and 4.2.0 are vulnerable.
TYPO3 is prone to a cross-site scripting vulnerability and a file-upload vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage the cross-site scripting issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks. The attacker can exploit the file-upload issue to execute arbitrary code in the context of the webserver.
TYPO3 3.x, 4.0 to 4.0.8, 4.1 to 4.1.6, and 4.2.0 are vulnerable.
Exploit / POC
TYPO3 Cross-Site Scripting Vulnerability and File Upload Vulnerability
An attacker can exploit these issues with a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting user into following a malicious URI.
An attacker can exploit these issues with a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting user into following a malicious URI.
Solution / Fix
TYPO3 Cross-Site Scripting Vulnerability and File Upload Vulnerability
Solution:
The vendor has released fixes. Please see the references for more information.
Solution:
The vendor has released fixes. Please see the references for more information.
References
TYPO3 Cross-Site Scripting Vulnerability and File Upload Vulnerability
References:
References: