Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-9509

Опубликовано: 04 янв. 2015
Источник: debian

Описание

The frontend rendering component in TYPO3 4.5.x before 4.5.39, 4.6.x through 6.2.x before 6.2.9, and 7.x before 7.0.2, when config.prefixLocalAnchors is set to all or cached, allows remote attackers to have an unspecified impact (possibly resource consumption) via a "Cache Poisoning" attack using a URL with arbitrary arguments, which triggers a reload of the page.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
typo3-srcremovedpackage
typo3-srcend-of-lifewheezypackage
typo3-srcend-of-lifesqueezepackage

Примечания

  • Solution is to remove he configuration options config.prefixLocalAnchors

  • (and optionally also config.baseUrl) in favor of config.absRefPrefix

Связанные уязвимости

ubuntu
около 11 лет назад

The frontend rendering component in TYPO3 4.5.x before 4.5.39, 4.6.x through 6.2.x before 6.2.9, and 7.x before 7.0.2, when config.prefixLocalAnchors is set to all or cached, allows remote attackers to have an unspecified impact (possibly resource consumption) via a "Cache Poisoning" attack using a URL with arbitrary arguments, which triggers a reload of the page.

nvd
около 11 лет назад

The frontend rendering component in TYPO3 4.5.x before 4.5.39, 4.6.x through 6.2.x before 6.2.9, and 7.x before 7.0.2, when config.prefixLocalAnchors is set to all or cached, allows remote attackers to have an unspecified impact (possibly resource consumption) via a "Cache Poisoning" attack using a URL with arbitrary arguments, which triggers a reload of the page.

github
больше 3 лет назад

Typo3 Vulnerable to Cache Poisoning