6.5
CVSSv2

CVE-2008-2717

Published: 16/06/2008 Updated: 11/10/2018
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

TYPO3 4.0.x prior to 4.0.9, 4.1.x prior to 4.1.7, and 4.2.x prior to 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which allows remote malicious users to bypass security restrictions and upload configuration files such as .htaccess, or conduct file upload attacks using multiple extensions.

Vulnerable Product Search on Vulmon Subscribe to Product

typo3 typo3 4.0.2

typo3 typo3 4.0.3

typo3 typo3 4.0.4

typo3 typo3 4.1.2

typo3 typo3 4.1.3

typo3 typo3 4.0.5

typo3 typo3 4.0.6

typo3 typo3 4.1.4

typo3 typo3 4.1.5

apache apache webserver

typo3 typo3 4.0.7

typo3 typo3 4.0.8

typo3 typo3 4.1.6

typo3 typo3 4.2

typo3 typo3 4.0

typo3 typo3 4.0.1

typo3 typo3 4.1

typo3 typo3 4.1.1

Vendor Advisories

Several remote vulnerabilities have been discovered in the TYPO3 content management framework Because of a not sufficiently secure default value of the TYPO3 configuration variable fileDenyPattern, authenticated backend users could upload files that allowed to execute arbitrary code as the webserver user User input processed by fe_adminlibinc is ...