CVE-2006-6690: High severity Typo3 TYPO3 vulnerability
rtehtmlarea/pi1/class.txrtehtmlareapi1.php in Typo3 4.0.0 through 4.0.3, 3.7 and 3.8 with the rtehtmlarea extension, and 4.1 beta allows remote authenticated users to execute arbitrary commands via shell metacharacters in the userUid parameter to rtehtmlarea/htmlarea/plugins/SpellChecker/spell-check-logic.php, and possibly another vector.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6690?
CVE-2006-6690 is rated as high severity due to the potential for remote command execution by authenticated users.
How do I fix CVE-2006-6690?
To fix CVE-2006-6690, upgrade Typo3 to version 4.0.4 or later, as these versions contain patches for this vulnerability.
Who is affected by CVE-2006-6690?
CVE-2006-6690 affects Typo3 versions 4.0.0 through 4.0.3, 3.7, and 3.8 when using the rtehtmlarea extension.
What types of attacks can exploit CVE-2006-6690?
CVE-2006-6690 can be exploited to execute arbitrary shell commands through crafted inputs to the userUid parameter.
Is authentication required to exploit CVE-2006-6690?
Yes, CVE-2006-6690 requires that the attacker be an authenticated user to exploit the vulnerability.