CVE-2008-2717: Malicious File Upload
TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which allows remote attackers to bypass security restrictions and upload configuration files such as .htaccess, or conduct file upload attacks using multiple extensions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2717?
CVE-2008-2717 is considered to have a medium severity due to the risk of remote code execution and unauthorized file uploads.
How do I fix CVE-2008-2717?
To fix CVE-2008-2717, upgrade TYPO3 to version 4.0.9, 4.1.7, or 4.2.1 or later.
What systems are affected by CVE-2008-2717?
CVE-2008-2717 affects TYPO3 versions 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1.
What types of attacks can be conducted due to CVE-2008-2717?
CVE-2008-2717 allows remote attackers to bypass security restrictions and potentially upload malicious configuration files, including .htaccess.
Is there a workaround for CVE-2008-2717?
Currently, the most effective workaround for CVE-2008-2717 is to restrict file upload permissions until the software is updated.