Описание
TYPO3 Directory Traversal vulnerability
Directory traversal vulnerability in the TypoScript setup in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 allows remote authenticated administrators to read arbitrary files via unspecified vectors related to the "file inclusion functionality."
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2010-5101
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64180
- https://web.archive.org/web/20120123102224/http://www.securityfocus.com/bid/45470
- https://web.archive.org/web/20121103085228/http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-sa-2010-022
- http://www.openwall.com/lists/oss-security/2011/01/13/2
- http://www.openwall.com/lists/oss-security/2012/05/10/7
- http://www.openwall.com/lists/oss-security/2012/05/11/3
- http://www.openwall.com/lists/oss-security/2012/05/12/5
Пакеты
typo3/cms
>= 4.2.0, < 4.2.16
4.2.16
typo3/cms
>= 4.3.0, < 4.3.9
4.3.9
typo3/cms
>= 4.4.0, < 4.4.5
4.4.5
Связанные уязвимости
Directory traversal vulnerability in the TypoScript setup in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 allows remote authenticated administrators to read arbitrary files via unspecified vectors related to the "file inclusion functionality."
Directory traversal vulnerability in the TypoScript setup in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 allows remote authenticated administrators to read arbitrary files via unspecified vectors related to the "file inclusion functionality."
Directory traversal vulnerability in the TypoScript setup in TYPO3 4.2 ...