HIGH
GHSA-4h9j-f98m-p4hg
TYPO3 PHP remote file inclusion vulnerability
Quick fix
GHSA-4h9j-f98m-p4hg — typo3/cms: upgrade to the fixed version with the command below.
composer require typo3/cms:^4.3.3Details
PHP remote file inclusion vulnerability in the autoloader in TYPO3 4.3.x before 4.3.3 allows remote attackers to execute arbitrary PHP code via a URL in an input field associated with the className variable.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2010-1153[ADVISORY]
- https://github.com/TYPO3/typo3[PACKAGE]
- https://web.archive.org/web/20100813082506/http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-008[WEB]
- http://marc.info/?l=oss-security&m=127092306209177&w=2[WEB]
- http://www.openwall.com/lists/oss-security/2010/04/12/1[WEB]