TYPO3 Photo Book Unspecified Directory Traversal Vulnerability
BID:37769
Info
TYPO3 Photo Book Unspecified Directory Traversal Vulnerability
| Bugtraq ID: | 37769 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 13 2010 12:00AM |
| Updated: | Jan 13 2010 12:00AM |
| Credit: | Peter Athmann |
| Vulnerable: |
Typo3 Photo Book 1.7.14 |
| Not Vulnerable: |
Typo3 Photo Book 1.7.15 |
Discussion
TYPO3 Photo Book Unspecified Directory Traversal Vulnerability
TYPO3 Photo Book ('goof_fotoboek') is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting the issue may allow an attacker to obtain sensitive information that could aid in further attacks.
Photo Book 1.7.14 and prior are vulnerable.
TYPO3 Photo Book ('goof_fotoboek') is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting the issue may allow an attacker to obtain sensitive information that could aid in further attacks.
Photo Book 1.7.14 and prior are vulnerable.
Exploit / POC
TYPO3 Photo Book Unspecified Directory Traversal Vulnerability
An attacker can exploit this issue via a browser.
An attacker can exploit this issue via a browser.
Solution / Fix
TYPO3 Photo Book Unspecified Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references for details.
Typo3 Photo Book 1.7.14
Solution:
Updates are available. Please see the references for details.
Typo3 Photo Book 1.7.14
-
Typo3 goof_fotoboek_1.7.15.t3x
http://typo3.org/fileadmin/ter/g/o/goof_fotoboek_1.7.15.t3x
References
TYPO3 Photo Book Unspecified Directory Traversal Vulnerability
References:
References:
- Synnefoims Homepage (synnefoims)
- TYPO3 Collective Security Bulletin TYPO3-SA-2009-021 (TYPO3)