6.8
CVSSv2

CVE-2011-4614

Published: 18/02/2012 Updated: 29/02/2012
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in Classes/Controller/AbstractController.php in the workspaces system extension in TYPO3 4.5.x prior to 4.5.9, 4.6.x prior to 4.6.2, and development versions of 4.7 allows remote malicious users to execute arbitrary PHP code via a URL in the BACK_PATH parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

typo3 typo3 4.5.2

typo3 typo3 4.5.3

typo3 typo3 4.5.4

typo3 typo3 4.5.5

typo3 typo3 4.5.1

typo3 typo3 4.5.6

typo3 typo3 4.5.8

typo3 typo3 4.5

typo3 typo3 4.5.7

typo3 typo3 4.6

typo3 typo3 4.6.1

Exploits

# Exploit Title: Typo3 v45-47 - Remote Code Execution (RFI/LFI) # Date: 4th January 2012 # Author: MaXe # Software Link: typo3org/download/ # Version: 450 up to 458, 460 and 461 (+ development releases of 47 branch) Typo3 v45-47 - Remote Code Execution (RFI/LFI) Versions Affected: 450 up to 458, 460 and 461 (+ ...