TYPO3 Simple download-system (kk_downloader) Unspecified Information Disclosure Vulnerability
BID:37168
Info
TYPO3 Simple download-system (kk_downloader) Unspecified Information Disclosure Vulnerability
| Bugtraq ID: | 37168 |
| Class: | Unknown |
| CVE: |
CVE-2009-4160 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 01 2009 12:00AM |
| Updated: | Apr 13 2015 09:05PM |
| Credit: | Georg Ringer |
| Vulnerable: |
Typo3 Simple download-system with counter and categories 1.2.1 |
| Not Vulnerable: |
Typo3 Simple download-system with counter and categories 1.2.2 |
Discussion
TYPO3 Simple download-system (kk_downloader) Unspecified Information Disclosure Vulnerability
TYPO3 Simple download-system (kk_downloader) is prone to an unspecified information-disclosure vulnerability.
Attackers can exploit this issue to harvest sensitive information that may lead to further attacks.
Versions prior to kk_downloader 1.2.2 are vulnerable.
TYPO3 Simple download-system (kk_downloader) is prone to an unspecified information-disclosure vulnerability.
Attackers can exploit this issue to harvest sensitive information that may lead to further attacks.
Versions prior to kk_downloader 1.2.2 are vulnerable.
Exploit / POC
TYPO3 Simple download-system (kk_downloader) Unspecified Information Disclosure Vulnerability
Attackers can exploit this issue via a web browser.
Attackers can exploit this issue via a web browser.
Solution / Fix
TYPO3 Simple download-system (kk_downloader) Unspecified Information Disclosure Vulnerability
Solution:
The vendor has released an update. Please see the references for details.
Typo3 Simple download-system with counter and categories 1.2.1
Solution:
The vendor has released an update. Please see the references for details.
Typo3 Simple download-system with counter and categories 1.2.1
-
Typo3 kk_downloader_1.2.2.t3x
http://typo3.org/fileadmin/ter/k/k/kk_downloader_1.2.2.t3x
References
TYPO3 Simple download-system (kk_downloader) Unspecified Information Disclosure Vulnerability
References:
References: