CVE-2009-3631: Code Injection
The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2, when the DAM extension or ftp upload is enabled, allows remote authenticated users to execute arbitrary commands via shell metacharacters in a filename.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3631?
CVE-2009-3631 is considered a high severity vulnerability due to its potential for remote command execution by authenticated users.
How do I fix CVE-2009-3631?
To fix CVE-2009-3631, update TYPO3 CMS to at least version 4.3beta2, 4.2.10, or 4.1.13.
Which TYPO3 versions are affected by CVE-2009-3631?
CVE-2009-3631 affects TYPO3 versions up to 4.3beta2, 4.2.9, and 4.1.12.
What type of attack does CVE-2009-3631 enable?
CVE-2009-3631 enables authenticated remote users to execute arbitrary commands through crafted filenames.
Is CVE-2009-3631 related to file uploads in TYPO3?
Yes, CVE-2009-3631 specifically involves vulnerabilities related to file uploads when the DAM extension or FTP upload is enabled.