← Back

CVE-2013-4250

nvd nist
Published: May 20, 2014Modified: May 6, 2026

JSON object

Loading...
6.5
Vector
AV:N/AC:L/Au:S/C:P/I:P/A:P
Exploitability: 8.0 / Impact: 6.4
Source: NVD

Description

The (1) file upload component and (2) File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.3 do not properly check file extensions, which allow remote authenticated editors to execute arbitrary PHP code by uploading a .php file.

Affected (12)

Products: Typo3: Typo3
1 product
Typo3
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Typo3
Version 6.0.1
Version 6.0.2
Version 6.0.3
Version 6.0.4
Version 6.0.5
Version 6.0.6
Version 6.0.7
Version 6.0.9
Version 6.0
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Typo3
Version 6.1.1
Version 6.1.2
Version 6.1

References (2)

Timeline

No history available yet.