CVE-2005-4875: Infoleak
Published Dec 31, 2005
·Updated
TYPO3 3.8.0 and earlier allows remote attackers to obtain sensitive information via a direct request to misc/phpcheck/, which invokes the phpinfo function and prints values of unspecified environment variables.
Affected Software
4 affected componentsFixes available
Typo3 TYPO3=1.1
Typo3 TYPO3=3.7.0
Typo3 TYPO3<=3.8.0
composer/typo3/cms<3.8.1
3.8.1
Event History
Dec 31, 2005
CVE Published
05:00 AM
May 19, 2008
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
May 1, 2022
Advisory Published
via GitHub·02:31 AM
Frequently Asked Questions
1
What is the severity of CVE-2005-4875?
CVE-2005-4875 is classified as a medium severity vulnerability due to its potential to expose sensitive information.
2
How do I fix CVE-2005-4875?
To fix CVE-2005-4875, upgrade TYPO3 to version 3.8.1 or later.
3
What versions of TYPO3 are affected by CVE-2005-4875?
CVE-2005-4875 affects TYPO3 versions 3.8.0 and earlier, including 1.1 and 3.7.0.
4
What type of vulnerability is CVE-2005-4875?
CVE-2005-4875 is a remote information disclosure vulnerability that allows attackers to access sensitive information.
5
Can CVE-2005-4875 be exploited remotely?
Yes, CVE-2005-4875 can be exploited remotely by sending direct requests to the vulnerable endpoint.