First published: Sat Dec 31 2005(Updated: )
TYPO3 3.8.0 and earlier allows remote attackers to obtain sensitive information via a direct request to misc/phpcheck/, which invokes the phpinfo function and prints values of unspecified environment variables.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Typo3 Typo3 | =1.1 | |
Typo3 Typo3 | =3.7.0 | |
Typo3 Typo3 | <=3.8.0 | |
TYPO3 | <=3.8.0 | |
TYPO3 | =1.1 | |
TYPO3 | =3.7.0 | |
composer/typo3/cms | <3.8.1 | 3.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4875 is classified as a medium severity vulnerability due to its potential to expose sensitive information.
To fix CVE-2005-4875, upgrade TYPO3 to version 3.8.1 or later.
CVE-2005-4875 affects TYPO3 versions 3.8.0 and earlier, including 1.1 and 3.7.0.
CVE-2005-4875 is a remote information disclosure vulnerability that allows attackers to access sensitive information.
Yes, CVE-2005-4875 can be exploited remotely by sending direct requests to the vulnerable endpoint.