VulnerabilityModified
CVE-2012-1607
The Command Line Interface (CLI) script in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attackers to obtain the database name via a direct request.
MEDIUM 5.0EPSS 3.09%
Does this matter?
Lower severity and a low EPSS score (3.09%). Track it; it rarely justifies an emergency change on its own.
Description
The Command Line Interface (CLI) script in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attackers to obtain the database name via a direct request.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 3.09% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- typo3/typo3
- Source
- secalert@redhat.com
References
- http://osvdb.org/80761
- http://secunia.com/advisories/48622Vendor Advisory
- http://secunia.com/advisories/48647Vendor Advisory
- http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2012-001/Vendor Advisory
- http://www.debian.org/security/2012/dsa-2445
- http://www.openwall.com/lists/oss-security/2012/03/30/4
- http://www.securityfocus.com/bid/52771
- http://osvdb.org/80761
- http://secunia.com/advisories/48622Vendor Advisory
- http://secunia.com/advisories/48647Vendor Advisory
- http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2012-001/Vendor Advisory
- http://www.debian.org/security/2012/dsa-2445
- http://www.openwall.com/lists/oss-security/2012/03/30/4
- http://www.securityfocus.com/bid/52771
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.