TYPO3 File Abstraction Layer Remote PHP Code Execution Vulnerability
BID:62257
Info
TYPO3 File Abstraction Layer Remote PHP Code Execution Vulnerability
| Bugtraq ID: | 62257 |
| Class: | Unknown |
| CVE: |
CVE-2013-4321 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 04 2013 12:00AM |
| Updated: | Sep 11 2013 12:11AM |
| Credit: | Sascha Egerer |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
TYPO3 File Abstraction Layer Remote PHP Code Execution Vulnerability
TYPO3 is prone to a remote PHP code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary PHP code within the context of the web server.
Versions prior to TYPO3 6.0.9 and 6.1.4 are vulnerable.
TYPO3 is prone to a remote PHP code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary PHP code within the context of the web server.
Versions prior to TYPO3 6.0.9 and 6.1.4 are vulnerable.
Exploit / POC
TYPO3 File Abstraction Layer Remote PHP Code Execution Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
TYPO3 File Abstraction Layer Remote PHP Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
TYPO3 File Abstraction Layer Remote PHP Code Execution Vulnerability
References:
References:
- TYPO3 Web Site (TYPO3)