TYPO3 Unspecified PHP Object Injection Vulnerability
BID:67630
Info
TYPO3 Unspecified PHP Object Injection Vulnerability
| Bugtraq ID: | 67630 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3942 |
| Remote: | Yes |
| Local: | No |
| Published: | May 22 2014 12:00AM |
| Updated: | Jun 23 2014 12:03AM |
| Credit: | Helmut Hummel |
| Vulnerable: |
Typo3 Typo3 4.5.13 Typo3 Typo3 4.7 Typo3 Typo3 4.5.3 Typo3 Typo3 4.5.2 Typo3 Typo3 4.5.15 Typo3 Typo3 4.5.1 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
TYPO3 Unspecified PHP Object Injection Vulnerability
TYPO3 is prone to a remote PHP object-injection vulnerability.
Attackers can exploit this issue to inject arbitrary object in to the application. This may allow an attacker to execute arbitrary PHP code through specially crafted serialized objects.
Typo3 4.5.0 through 4.5.33, 4.7.0 through 4.7.18, 6.0.0 through 6.0.13 and 6.1.0 through 6.1.8 are vulnerable.
TYPO3 is prone to a remote PHP object-injection vulnerability.
Attackers can exploit this issue to inject arbitrary object in to the application. This may allow an attacker to execute arbitrary PHP code through specially crafted serialized objects.
Typo3 4.5.0 through 4.5.33, 4.7.0 through 4.7.18, 6.0.0 through 6.0.13 and 6.1.0 through 6.1.8 are vulnerable.
Exploit / POC
TYPO3 Unspecified PHP Object Injection Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
TYPO3 Unspecified PHP Object Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.