← Back

CVE-2012-3527

nvd nist
Published: Sep 5, 2012Modified: Apr 29, 2026

JSON object

Loading...
4.6
Vector
AV:N/AC:H/Au:S/C:P/I:P/A:P
Exploitability: 3.9 / Impact: 6.4
Source: NVD

Description

view_help.php in the backend help system in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote authenticated backend users to unserialize arbitrary objects and possibly execute arbitrary PHP code via an unspecified parameter, related to a "missing signature (HMAC)."

Affected (5)

1 product
Typo3
1 product
Debian Linux
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Typo3
From 4.5.0 to 4.5.19
From 4.6.0 to 4.6.12
From 4.7.0 to 4.7.4
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 6.0
Version 7.0

References (12)

Source: secalert@redhat.com
Broken Link
Source: secalert@redhat.com
Not Applicable
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Mailing List
Source: secalert@redhat.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.