Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-3663

Опубликовано: 04 нояб. 2019
Источник: nvd
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains an insecure default value of the variable fileDenyPattern which could allow remote attackers to execute arbitrary code on the backend.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
Версия до 4.1.14 (исключая)
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
Версия от 4.2.0 (включая) до 4.2.13 (исключая)
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
Версия от 4.3.0 (включая) до 4.3.4 (исключая)
cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*
Версия от 4.4.0 (включая) до 4.4.1 (исключая)

EPSS

Процентиль: 82%
0.02395
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 7 лет назад

TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains an insecure default value of the variable fileDenyPattern which could allow remote attackers to execute arbitrary code on the backend.

CVSS3: 8.8
debian
почти 7 лет назад

TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x ...

CVSS3: 8.8
github
больше 4 лет назад

TYPO3 Arbitrary Code Execution vulnerability on the backend

EPSS

Процентиль: 82%
0.02395
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-434