CVE-2011-4614
PHP remote file inclusion vulnerability in Classes/Controller/AbstractController.php in the workspaces system extension in TYPO3 4.5.x before 4.5.9, 4.6.x before 4.6.2, and development versions of 4.7 allows remote attackers to execute arbitrary PHP…
Does this matter?
Lower severity and a low EPSS score (5.63%). Track it; it rarely justifies an emergency change on its own.
Description
PHP remote file inclusion vulnerability in Classes/Controller/AbstractController.php in the workspaces system extension in TYPO3 4.5.x before 4.5.9, 4.6.x before 4.6.2, and development versions of 4.7 allows remote attackers to execute arbitrary PHP code via a URL in the BACK_PATH parameter.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 5.63% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- typo3/typo3
- Source
- secalert@redhat.com
References
- http://secunia.com/advisories/47201Vendor Advisory
- http://typo3.org/fileadmin/security-team/bug32571/32571.diff
- http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2011-004/Patch, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2011/12/16/1
- http://www.osvdb.org/77776
- http://secunia.com/advisories/47201Vendor Advisory
- http://typo3.org/fileadmin/security-team/bug32571/32571.diff
- http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2011-004/Patch, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2011/12/16/1
- http://www.osvdb.org/77776
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.