TYPO3 Security - Salted User Password Hashes Security Bypass Vulnerability
BID:38799
Info
TYPO3 Security - Salted User Password Hashes Security Bypass Vulnerability
| Bugtraq ID: | 38799 |
| Class: | Access Validation Error |
| CVE: |
CVE-2010-1022 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 17 2010 12:00AM |
| Updated: | Apr 13 2015 09:02PM |
| Credit: | Marcus Krause |
| Vulnerable: |
Typo3 TYPO3 Security - Salted user password hashes 0.2.12 |
| Not Vulnerable: |
Typo3 TYPO3 Security - Salted user password hashes 0.2.13 |
Discussion
TYPO3 Security - Salted User Password Hashes Security Bypass Vulnerability
TYPO3 Security - Salted user password hashes is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to gain unauthorized access to the affected application.
TYPO3 Security - Salted user password hashes 0.2.12 and prior are vulnerable
TYPO3 Security - Salted user password hashes is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to gain unauthorized access to the affected application.
TYPO3 Security - Salted user password hashes 0.2.12 and prior are vulnerable
Exploit / POC
TYPO3 Security - Salted User Password Hashes Security Bypass Vulnerability
Attackers can exploit this issue via a browser.
Attackers can exploit this issue via a browser.
Solution / Fix
TYPO3 Security - Salted User Password Hashes Security Bypass Vulnerability
Solution:
The vendor has released a fix. Please see the references for details.
Typo3 TYPO3 Security - Salted user password hashes 0.2.12
Solution:
The vendor has released a fix. Please see the references for details.
Typo3 TYPO3 Security - Salted user password hashes 0.2.12
-
Typo3 t3sec_saltedpw_0.2.13.t3x
http://typo3.org/fileadmin/ter/t/3/t3sec_saltedpw_0.2.13.t3x
References
TYPO3 Security - Salted User Password Hashes Security Bypass Vulnerability
References:
References:
- TYPO3 Collective Security Bulletin TYPO3-SA-2010-006 (TYPO3)
- TYPO3 Homepage (TYPO3)