Description
The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2, when the DAM extension or ftp upload is enabled, allows remote authenticated users to execute arbitrary commands via shell metacharacters in a filename.
Remediation
References
Related Vulnerabilities
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-3278)
WordPress Plugin Aspose PDF Exporter Arbitrary File Download (1.0)
Ruby on Rails URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2021-22942)
WordPress Plugin Advanced Contact form 7 DB Arbitrary File Upload (1.4.4)
Sqlite Improper Check for Unusual or Exceptional Conditions Vulnerability (CVE-2019-19646)