VulnerabilityModified
CVE-2010-5101
Directory traversal vulnerability in the TypoScript setup in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 allows remote authenticated administrators to read arbitrary files via unspecified vectors related to the "file inclusion…
MEDIUM 4.0EPSS 1.95%
Does this matter?
Lower severity and a low EPSS score (1.95%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in the TypoScript setup in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 allows remote authenticated administrators to read arbitrary files via unspecified vectors related to the "file inclusion functionality."
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
- EPSS
- 1.95% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- typo3/typo3
- Source
- secalert@redhat.com
References
- http://secunia.com/advisories/35770Vendor Advisory
- http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-sa-2010-022/Vendor Advisory
- http://www.openwall.com/lists/oss-security/2011/01/13/2
- http://www.openwall.com/lists/oss-security/2012/05/10/7
- http://www.openwall.com/lists/oss-security/2012/05/11/3
- http://www.openwall.com/lists/oss-security/2012/05/12/5
- http://www.osvdb.org/70119
- http://www.securityfocus.com/bid/45470
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64180
- http://secunia.com/advisories/35770Vendor Advisory
- http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-sa-2010-022/Vendor Advisory
- http://www.openwall.com/lists/oss-security/2011/01/13/2
- http://www.openwall.com/lists/oss-security/2012/05/10/7
- http://www.openwall.com/lists/oss-security/2012/05/11/3
- http://www.openwall.com/lists/oss-security/2012/05/12/5
- http://www.osvdb.org/70119
- http://www.securityfocus.com/bid/45470
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64180
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.