← Back

CVE-2013-4321

nvd nist
Published: May 20, 2014Modified: May 6, 2026

JSON object

Loading...
6.5
Vector
AV:N/AC:L/Au:S/C:P/I:P/A:P
Exploitability: 8.0 / Impact: 6.4
Source: NVD

Description

The File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.4 allows remote authenticated editors to execute arbitrary PHP code via unspecified characters in the file extension when renaming a file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4250.

Affected (12)

Products: Typo3: Typo3
1 product
Typo3
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Typo3
Version 6.1.1
Version 6.1.2
Version 6.1.3
Version 6.1
Configuration B
8 vulnerable
Vulnerable SoftwareAffected Versions
Typo3
Version 6.0.1
Version 6.0.2
Version 6.0.3
Version 6.0.4
Version 6.0.5
Version 6.0.6
Version 6.0.7
Version 6.0

References (2)

Timeline

No history available yet.