7.1
CVSSv2

CVE-2010-3714

Published: 25/10/2010 Updated: 01/06/2012
CVSS v2 Base Score: 7.1 | Impact Score: 6.9 | Exploitability Score: 8.6
VMScore: 715
Vector: AV:N/AC:M/Au:N/C:C/I:N/A:N

Vulnerability Summary

The jumpUrl (aka access tracking) implementation in tslib/class.tslib_fe.php in TYPO3 4.2.x prior to 4.2.15, 4.3.x prior to 4.3.7, and 4.4.x prior to 4.4.4 does not properly compare certain hash values during access-control decisions, which allows remote malicious users to read arbitrary files via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

typo3 typo3 4.2.3

typo3 typo3 4.2.2

typo3 typo3 4.2.1

typo3 typo3 4.3.0

typo3 typo3 4.3.1

typo3 typo3 4.4.2

typo3 typo3 4.4.3

typo3 typo3 4.2.9

typo3 typo3 4.2.0

typo3 typo3 4.2.13

typo3 typo3 4.2.14

typo3 typo3 4.3.6

typo3 typo3 4.4

typo3 typo3 4.4.1

typo3 typo3 4.2.7

typo3 typo3 4.2.8

typo3 typo3 4.2.11

typo3 typo3 4.2.12

typo3 typo3 4.3.4

typo3 typo3 4.3.5

typo3 typo3 4.2.5

typo3 typo3 4.2.6

typo3 typo3 4.2.4

typo3 typo3 4.2.10

typo3 typo3 4.3.2

typo3 typo3 4.3.3

Vendor Advisories

Several remote vulnerabilities have been discovered in TYPO3 The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2010-3714 Multiple remote file disclosure vulnerabilities in the jumpUrl mechanism and the Extension Manager allowed attackers to read files with the privileges of the account under which the web ...

Exploits

<?php /* TYPO3-SA-2010-022php * Exploit Title: TYPO3 Unauthenticated Arbitrary File Retrieval (TYPO3-SA-2010-020, TYPO3-SA-2010-022) * Date: 29/12/2010 * Author: ikki * Software Link: typo3org/download/, sourceforgenet/projects/typo3/files/ * Version: 4215, 437 or 444 * Tested on: php * CVE : CVE-2010-3714 (non-typ ...
TYPO3 unauthenticated arbitrary file retrieval exploit Affects versions 4215, 437, and 444 ...