Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2012-1605

Опубликовано: 04 сент. 2012
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 5

Описание

The Extbase Framework in TYPO3 4.6.x through 4.6.6, 4.7, and 6.0 unserializes untrusted data, which allows remote attackers to unserialize arbitrary objects and possibly execute arbitrary code via vectors related to "a missing signature (HMAC) for a request argument." To our knowledge it is neither possible to inject code through this vulnerability, nor are there exploitable objects within the TYPO3 Core. However, there might be exploitable objects within third party extensions.

РелизСтатусПримечание
devel

not-affected

hardy

ignored

end of life
lucid

ignored

end of life
maverick

ignored

end of life
natty

ignored

end of life
oneiric

not-affected

precise

not-affected

quantal

not-affected

raring

not-affected

saucy

not-affected

Показывать по

EPSS

Процентиль: 82%
0.02365
Низкий

5 Medium

CVSS2

Связанные уязвимости

nvd
почти 14 лет назад

The Extbase Framework in TYPO3 4.6.x through 4.6.6, 4.7, and 6.0 unserializes untrusted data, which allows remote attackers to unserialize arbitrary objects and possibly execute arbitrary code via vectors related to "a missing signature (HMAC) for a request argument."

debian
почти 14 лет назад

The Extbase Framework in TYPO3 4.6.x through 4.6.6, 4.7, and 6.0 unser ...

github
больше 4 лет назад

Typo3 Extbase Framework Unsafe Deserialization

EPSS

Процентиль: 82%
0.02365
Низкий

5 Medium

CVSS2