Component Type: TYPO3 Core
Affected Versions: 4.3.0, 4.3.1 and 4.3.2 (+ development releases of 4.4 branch)
Vulnerability Types: Remote Command Execution
Overall Severity: Critical
Release Date: April 9, 2010
Vulnerability Type: Remote Command Execution
Severity: Critical
Suggested CVSS v2.0: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C (What's that?)
Problem Description: The TYPO3 autoloader does not validate passed arguments.
You are not vulnerable if at least one of following conditions is met:
Possible Impact: A crafted request to a vulnerable TYPO3 installation will allow an attacker to load PHP code from an external server and to execute it on the TYPO3 installation.
Solution: You can choose one of the solutions below:
Patch: how to patch
Files: Extract the archive and replace server files with those that are in the archive
Note: We have been informed that this vulnerability has already been exploited.
Credits: Credits go to Christian Bülter and Bastian Heiser who discovered and reported the issue and the Security Team members Dmitry Dulepov, Marcus Krause and Helmut Hummel for providing the mod_security rule and the patch.
General Advice: Follow the recommendations that are given in the TYPO3 Security Cookbook. Please subscribe to the typo3-announce mailing list.