7.5
CVSSv2

CVE-2006-6690

Published: 21/12/2006 Updated: 17/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

rtehtmlarea/pi1/class.tx_rtehtmlarea_pi1.php in Typo3 4.0.0 up to and including 4.0.3, 3.7 and 3.8 with the rtehtmlarea extension, and 4.1 beta allows remote authenticated users to execute arbitrary commands via shell metacharacters in the userUid parameter to rtehtmlarea/htmlarea/plugins/SpellChecker/spell-check-logic.php, and possibly another vector.

Vulnerable Product Search on Vulmon Subscribe to Product

typo3 typo3 4.0

typo3 typo3 4.0.1

typo3 typo3 3.7.0

typo3 typo3 3.8

typo3 typo3 4.0.2

typo3 typo3 4.0.3

Exploits

source: wwwsecurityfocuscom/bid/21680/info TYPO3 is prone to multiple vulnerabilities that allow attackers to execute arbitrary commands This issue occurs because the application fails to properly sanitize user-supplied data Exploiting these issues allows unauthenticated attackers to execute arbitrary system commands with the privilege ...