TYPO3 Simple File Browser Unspecified Information Disclosure Vulnerability
BID:32984
Info
TYPO3 Simple File Browser Unspecified Information Disclosure Vulnerability
| Bugtraq ID: | 32984 |
| Class: | Unknown |
| CVE: |
CVE-2008-6342 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 23 2008 12:00AM |
| Updated: | Mar 06 2009 09:16PM |
| Credit: | Werner Modenbach |
| Vulnerable: |
Typo3 Simple File Browser 1.0.2 |
| Not Vulnerable: |
Typo3 Simple File Browser 1.0.3 |
Discussion
TYPO3 Simple File Browser Unspecified Information Disclosure Vulnerability
TYPO3 Simple File Browser ('simplefilebrowser') is prone to an unspecified information-disclosure vulnerability.
Attackers can exploit this issue to harvest sensitive information that may lead to further attacks.
Simple File Browser 1.0.2 is vulnerable; other versions may also be affected.
TYPO3 Simple File Browser ('simplefilebrowser') is prone to an unspecified information-disclosure vulnerability.
Attackers can exploit this issue to harvest sensitive information that may lead to further attacks.
Simple File Browser 1.0.2 is vulnerable; other versions may also be affected.
Exploit / POC
TYPO3 Simple File Browser Unspecified Information Disclosure Vulnerability
Attackers can exploit this issue via a web browser.
Attackers can exploit this issue via a web browser.
Solution / Fix
TYPO3 Simple File Browser Unspecified Information Disclosure Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Typo3 Simple File Browser 1.0.2
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Typo3 Simple File Browser 1.0.2
-
Typo3 simplefilebrowser_1.0.3.t3x
http://typo3.org/fileadmin/ter/s/i/simplefilebrowser_1.0.3.t3x
References
TYPO3 Simple File Browser Unspecified Information Disclosure Vulnerability
References:
References:
- Synnefoims Homepage (synnefoims)
- TYPO3 Collective Security Bulletin TYPO3-20081222-4 (Typo3)