Summary
This host is installed with TYPO3 and is prone to code execution vulnerability.
Impact
Successful exploitation will allow remote attackers to execute arbitary commands.
Impact Level: System/Application
Solution
Upgrade to TYPO3 version 6.0.8, 6.1.3 or later,
For updates refer to, http://typo3.org/
Insight
An error exist in file upload component and the File Abstraction Layer, which allows to upload PHP files with arbitary code.
Affected
TYPO3 version 6.0.0 to 6.0.7, 6.1.0 to 6.1.2
Detection
Get the installed version with the help of detect NVT and check the version is vulnerable or not.
References
Severity
Classification
-
CVE CVE-2013-4250 -
CVSS Base Score: 6.5
AV:N/AC:L/Au:S/C:P/I:P/A:P
Related Vulnerabilities
- Ampache Reflected Cross Site Scripting Vulnerability
- @Mail 'admin.php' Cross-Site Scripting Vulnerabilities
- AeroMail Cross Site Request Forgery, HTML Injection and Cross Site Scripting Vulnerabilities
- Apache Tomcat RemoteFilterValve Security Bypass Vulnerability
- Adobe BlazeDS XML and XML External Entity Injection Vulnerabilities