Typo3 Translations.PHP File Disclosure Vulnerability
BID:6985
Info
Typo3 Translations.PHP File Disclosure Vulnerability
| Bugtraq ID: | 6985 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 28 2003 12:00AM |
| Updated: | Feb 28 2003 12:00AM |
| Credit: | Discovery of this issue is credited to Martin Eiszner <[email protected]>. |
| Vulnerable: |
Typo3 Typo3 3.5 b5 |
| Not Vulnerable: |
Typo3 Typo3 3.5 .0 |
Discussion
Typo3 Translations.PHP File Disclosure Vulnerability
TYPO3 does not sufficiently sanitize input submitted via URI parameters of potentially malicious data. This issue exists in the 'translations.php' script. By submitting a malicious web request to this script that contains a relative path to a resource and a null character (%00), it is possible to retrieve arbitrary files that are readable by the web server process.
TYPO3 does not sufficiently sanitize input submitted via URI parameters of potentially malicious data. This issue exists in the 'translations.php' script. By submitting a malicious web request to this script that contains a relative path to a resource and a null character (%00), it is possible to retrieve arbitrary files that are readable by the web server process.
Exploit / POC
Typo3 Translations.PHP File Disclosure Vulnerability
This issue may be exploited with a web browser.
This issue may be exploited with a web browser.