CVE-2010-1153: Code Injection
Published Apr 20, 2010
·Updated
PHP remote file inclusion vulnerability in the autoloader in TYPO3 4.3.x before 4.3.3 allows remote attackers to execute arbitrary PHP code via a URL in an input field associated with the className variable.
Affected Software
4 affected componentsFixes available
Typo3 TYPO3=4.3.2
Typo3 TYPO3=4.3.0
Typo3 TYPO3=4.3.1
composer/typo3/cms>=4.3.0<4.3.3
4.3.3
Event History
Apr 20, 2010
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:30 PM
DescriptionSeverityWeaknessAffected Software
May 2, 2022
Advisory Published
via GitHub·06:19 AM
Frequently Asked Questions
1
What is the severity of CVE-2010-1153?
CVE-2010-1153 has a critical severity level as it allows remote code execution due to improper input handling.
2
How do I fix CVE-2010-1153?
To fix CVE-2010-1153, upgrade TYPO3 to version 4.3.3 or later.
3
Which versions of TYPO3 are affected by CVE-2010-1153?
CVE-2010-1153 affects TYPO3 versions 4.3.0, 4.3.1, and 4.3.2.
4
What type of vulnerability is CVE-2010-1153?
CVE-2010-1153 is a remote file inclusion vulnerability.
5
Can CVE-2010-1153 be exploited remotely?
Yes, CVE-2010-1153 can be exploited remotely by an attacker to execute arbitrary PHP code.