CVE-2014-3941: Input Validation
Possible Host Spoofing through SERVERNAME
Other sources
TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, 6.1.0 before 6.1.9, and 6.2.0 before 6.2.3 allows remote attackers to have unspecified impact via a crafted HTTP Host header, related to "Host Spoofing."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3941?
CVE-2014-3941 has a moderate severity rating due to its potential for host spoofing.
How do I fix CVE-2014-3941?
To fix CVE-2014-3941, upgrade TYPO3 to versions 4.5.34, 4.7.19, 6.0.14, 6.1.9, or 6.2.3.
What versions of TYPO3 are affected by CVE-2014-3941?
Poorly configured versions of TYPO3 prior to 4.5.34, 4.7.19, 6.0.14, 6.1.9, and 6.2.3 are affected by CVE-2014-3941.
What type of vulnerability is CVE-2014-3941?
CVE-2014-3941 is classified as a host spoofing vulnerability due to improper handling of the HTTP Host header.
Can CVE-2014-3941 be exploited remotely?
Yes, CVE-2014-3941 can be exploited remotely by attackers through crafted HTTP Host headers.