CVE-2012-1607: Infoleak
The Command Line Interface (CLI) script in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attackers to obtain the database name via a direct request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1607?
CVE-2012-1607 is considered a moderate severity vulnerability due to unauthorized database access risk.
How do I fix CVE-2012-1607?
To fix CVE-2012-1607, update TYPO3 to version 4.4.14, 4.5.14, 4.6.7, 4.7.1, or later versions.
What versions of TYPO3 are affected by CVE-2012-1607?
CVE-2012-1607 affects TYPO3 versions 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0.
What type of vulnerability is CVE-2012-1607?
CVE-2012-1607 is a remote information disclosure vulnerability that allows attackers to obtain sensitive database details.
Can CVE-2012-1607 be exploited remotely?
Yes, CVE-2012-1607 can be exploited remotely by attackers making direct requests to the affected TYPO3 installations.