[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250053

 
 

909

 
 

195940

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2006-6690Date: (C)2006-12-21   (M)2023-12-22


rtehtmlarea/pi1/class.tx_rtehtmlarea_pi1.php in Typo3 4.0.0 through 4.0.3, 3.7 and 3.8 with the rtehtmlarea extension, and 4.1 beta allows remote authenticated users to execute arbitrary commands via shell metacharacters in the userUid parameter to rtehtmlarea/htmlarea/plugins/SpellChecker/spell-check-logic.php, and possibly another vector.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1017428
http://www.securityfocus.com/archive/1/archive/1/454944/100/0/threaded
SREASON-2056
BID-21680
SECUNIA-23446
SECUNIA-23466
ADV-2006-5094
http://lists.netfielders.de/pipermail/typo3-announce/2006/000045.html
http://lists.netfielders.de/pipermail/typo3-announce/2006/000046.html
http://typo3.org/news-single-view/?tx_newsimporter_pi1%5BshowItem%5D=0&cHash=e4a40a11a9
http://www.sec-consult.com/272.html

CPE    4
cpe:/a:typo3:typo3:4.0.3
cpe:/a:typo3:typo3:4.0.2
cpe:/a:typo3:typo3:4.0.1
cpe:/a:typo3:typo3:4.0
...

© SecPod Technologies