Description
TYPO3 before 4.4.9 and 4.5.x before 4.5.4 does not apply proper access control on ExtDirect calls which allows remote attackers to retrieve ExtDirect endpoint services.
Remediation
References
Related Vulnerabilities
WordPress Plugin Spellchecker 'general.php' Local and Remote File Include Vulnerabilities (3.1)
WordPress Plugin Ajax Pagination (twitter Style) Local File Inclusion (1.1)
Oracle Database Server CVE-2006-0291 Vulnerability (CVE-2006-0291)
e107 Inadequate Encryption Strength Vulnerability (CVE-2021-27885)