Description
The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2, when the DAM extension or ftp upload is enabled, allows remote authenticated users to execute arbitrary commands via shell metacharacters in a filename.
Remediation
References
Related Vulnerabilities
MySQL CVE-2015-4836 Vulnerability (CVE-2015-4836)
Drupal Credentials Management Errors Vulnerability (CVE-2009-2374)
WordPress Plugin Flip Book 'php.php' Arbitrary File Upload (1.0)
Envoy Proxy Use After Free Vulnerability (CVE-2021-43826)
WordPress Plugin FeedWordPress Cross-Site Scripting (2014.0805)