The (1) file upload component and (2) File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.3 do not properly check file extensions, which allow remote authenticated editors to execute arbitrary PHP code by uploading a .php file.
2014-05-20T14:55:04.147
2025-04-12T10:46:40.837
Deferred
CVSSv2: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | typo3 | typo3 | 6.0 | Yes |
Application | typo3 | typo3 | 6.0.1 | Yes |
Application | typo3 | typo3 | 6.0.2 | Yes |
Application | typo3 | typo3 | 6.0.3 | Yes |
Application | typo3 | typo3 | 6.0.4 | Yes |
Application | typo3 | typo3 | 6.0.5 | Yes |
Application | typo3 | typo3 | 6.0.6 | Yes |
Application | typo3 | typo3 | 6.0.7 | Yes |
Application | typo3 | typo3 | 6.0.9 | Yes |
Application | typo3 | typo3 | 6.1 | Yes |
Application | typo3 | typo3 | 6.1.1 | Yes |
Application | typo3 | typo3 | 6.1.2 | Yes |