First published: Mon Nov 04 2019(Updated: )
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains an insecure default value of the variable fileDenyPattern which could allow remote attackers to execute arbitrary code on the backend.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Typo3 Typo3 | >=4.4.0<4.4.1 | |
Typo3 Typo3 | >=4.3.0<4.3.4 | |
Typo3 Typo3 | <4.1.14 | |
Typo3 Typo3 | >=4.2.0<4.2.13 | |
composer/typo3/cms-backend | >=4.4<4.4.1 | 4.4.1 |
composer/typo3/cms-backend | >=4.3<4.3.4 | 4.3.4 |
composer/typo3/cms-backend | >=4.2<4.2.13 | 4.2.13 |
composer/typo3/cms-backend | <4.1.14 | 4.1.14 |
debian/typo3-src | ||
<4.1.14 | ||
>=4.2.0<4.2.13 | ||
>=4.3.0<4.3.4 | ||
>=4.4.0<4.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3663 is a vulnerability in TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4, and 4.4.x before 4.4.1 that allows remote attackers to execute arbitrary code on the backend.
CVE-2010-3663 has a severity score of 8.8 out of 10.
The affected software for CVE-2010-3663 is TYPO3 versions before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4, and 4.4.x before 4.4.1.
To fix CVE-2010-3663, update TYPO3 to version 4.1.14, 4.2.13, 4.3.4, or 4.4.1.
You can find more information about CVE-2010-3663 at the TYPO3 security advisory and Debian security tracker websites.