First published: Thu Dec 21 2006(Updated: )
rtehtmlarea/pi1/class.tx_rtehtmlarea_pi1.php in Typo3 4.0.0 through 4.0.3, 3.7 and 3.8 with the rtehtmlarea extension, and 4.1 beta allows remote authenticated users to execute arbitrary commands via shell metacharacters in the userUid parameter to rtehtmlarea/htmlarea/plugins/SpellChecker/spell-check-logic.php, and possibly another vector.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Typo3 Typo3 | =4.0.3 | |
Typo3 Typo3 | =4.0.1 | |
Typo3 Typo3 | =4.0.2 | |
Typo3 Typo3 | =4.0 | |
Typo3 Typo3 | =3.7.0 | |
Typo3 Typo3 | =3.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.