CVE-2011-4614: Code Injection
Published Feb 18, 2012
·Updated
PHP remote file inclusion vulnerability in Classes/Controller/AbstractController.php in the workspaces system extension in TYPO3 4.5.x before 4.5.9, 4.6.x before 4.6.2, and development versions of 4.7 allows remote attackers to execute arbitrary PHP code via a URL in the BACKPATH parameter.
Affected Software
11 affected components
Typo3 TYPO3=4.5.3
Typo3 TYPO3=4.5.5
Typo3 TYPO3=4.5.8
Typo3 TYPO3=4.5.7
Typo3 TYPO3=4.5.6
Typo3 TYPO3=4.5
Typo3 TYPO3=4.5.1
Typo3 TYPO3=4.5.4
Typo3 TYPO3=4.5.2
Typo3 TYPO3=4.6
Typo3 TYPO3=4.6.1
Remediation
Event History
Feb 18, 2012
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-4614?
CVE-2011-4614 is classified as a critical vulnerability due to its ability to allow remote code execution.
2
How do I fix CVE-2011-4614?
To fix CVE-2011-4614, upgrade TYPO3 to version 4.5.9, 4.6.2 or later.
3
What versions of TYPO3 are affected by CVE-2011-4614?
CVE-2011-4614 affects TYPO3 versions 4.5.x prior to 4.5.9 and 4.6.x prior to 4.6.2.
4
What type of attack does CVE-2011-4614 enable?
CVE-2011-4614 enables remote attackers to execute arbitrary PHP code.
5
Is it safe to use TYPO3 4.5.x after applying patches for CVE-2011-4614?
It is generally not safe to use TYPO3 4.5.x without upgrading, even with patches, as newer vulnerabilities could still exist.