CVE Vulnerabilities

CVE-2008-2717

Published: Jun 16, 2008 | Modified: Oct 11, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which allows remote attackers to bypass security restrictions and upload configuration files such as .htaccess, or conduct file upload attacks using multiple extensions.

Affected Software

Name Vendor Start Version End Version
Apache_webserver Apache * *
Typo3 Typo3 4.0 4.0
Typo3 Typo3 4.0.1 4.0.1
Typo3 Typo3 4.0.2 4.0.2
Typo3 Typo3 4.0.3 4.0.3
Typo3 Typo3 4.0.4 4.0.4
Typo3 Typo3 4.0.5 4.0.5
Typo3 Typo3 4.0.6 4.0.6
Typo3 Typo3 4.0.7 4.0.7
Typo3 Typo3 4.0.8 4.0.8
Typo3 Typo3 4.1 4.1
Typo3 Typo3 4.1.1 4.1.1
Typo3 Typo3 4.1.2 4.1.2
Typo3 Typo3 4.1.3 4.1.3
Typo3 Typo3 4.1.4 4.1.4
Typo3 Typo3 4.1.5 4.1.5
Typo3 Typo3 4.1.6 4.1.6
Typo3 Typo3 4.2 4.2
Typo3-src Ubuntu dapper *
Typo3-src Ubuntu hardy *
Typo3-src Ubuntu upstream *

References