Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2012-1605

Опубликовано: 04 сент. 2012
Источник: ubuntu
Приоритет: low
CVSS2: 5

Описание

The Extbase Framework in TYPO3 4.6.x through 4.6.6, 4.7, and 6.0 unserializes untrusted data, which allows remote attackers to unserialize arbitrary objects and possibly execute arbitrary code via vectors related to "a missing signature (HMAC) for a request argument." To our knowledge it is neither possible to inject code through this vulnerability, nor are there exploitable objects within the TYPO3 Core. However, there might be exploitable objects within third party extensions.

РелизСтатусПримечание
devel

not-affected

hardy

ignored

end of life
lucid

ignored

end of life
maverick

ignored

end of life
natty

ignored

end of life
oneiric

not-affected

precise

not-affected

quantal

not-affected

raring

not-affected

saucy

not-affected

Показывать по

5 Medium

CVSS2

Связанные уязвимости

nvd
больше 13 лет назад

The Extbase Framework in TYPO3 4.6.x through 4.6.6, 4.7, and 6.0 unserializes untrusted data, which allows remote attackers to unserialize arbitrary objects and possibly execute arbitrary code via vectors related to "a missing signature (HMAC) for a request argument."

debian
больше 13 лет назад

The Extbase Framework in TYPO3 4.6.x through 4.6.6, 4.7, and 6.0 unser ...

github
больше 3 лет назад

Typo3 Extbase Framework Unsafe Deserialization

5 Medium

CVSS2