Typo3 ‘Class.TX_RTEHTMLArea_PI1.PHP’多个远程命令执行漏洞

漏洞信息详情

Typo3 ‘Class.TX_RTEHTMLArea_PI1.PHP’多个远程命令执行漏洞

漏洞简介

Typo3 4.0.0至4.0.3、带有rtehtmlarea扩展的3.7和3.8版,以及4.1 beta版中的rtehtmlarea/pi1/class.tx_rtehtmlarea_pi1.php存在远程命令执行漏洞。远程认证用户通过传给rtehtmlarea/htmlarea/plugins/SpellChecker/spell-check-logic.php的userUid参数中的shell元字符,以及可能的其他向量,来执行任意命令。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

Typo3 Typo3 3.8

Typo3 typo3_src-4.0.4.tar.gz

http://prdownloads.sourceforge.net/typo3/typo3_src-4.0.4.tar.gz?download

Typo3 Typo3 4.0

Typo3 typo3_src-4.0.4.tar.gz

http://prdownloads.sourceforge.net/typo3/typo3_src-4.0.4.tar.gz?download

Typo3 Typo3 3.7 .0

Typo3 typo3_src-4.0.4.tar.gz

http://prdownloads.sourceforge.net/typo3/typo3_src-4.0.4.tar.gz?download

Typo3 Typo3 4.0.1

Typo3 typo3_src-4.0.4.tar.gz

http://prdownloads.sourceforge.net/typo3/typo3_src-4.0.4.tar.gz?download

Typo3 Typo3 4.0.2

Typo3 typo3_src-4.0.4.tar.gz

http://prdownloads.sourceforge.net/typo3/typo3_src-4.0.4.tar.gz?download

Typo3 Typo3 4.0.3

Typo3 typo3_src-4.0.4.tar.gz

http://prdownloads.sourceforge.net/typo3/typo3_src-4.0.4.tar.gz?download

参考网址

来源: BID

名称: 21680

链接:http://www.securityfocus.com/bid/21680

来源: VUPEN

名称: ADV-2006-5094

链接:http://www.frsirt.com/english/advisories/2006/5094

来源: SECTRACK

名称: 1017428

链接:http://securitytracker.com/id?1017428

来源: SECUNIA

名称: 23466

链接:http://secunia.com/advisories/23466

来源: SECUNIA

名称: 23446

链接:http://secunia.com/advisories/23446

来源: BUGTRAQ

名称: 20061220 SEC Consult SA-20061220-0 :: Typo3 Command Execution Vulnerability

链接:http://www.securityfocus.com/archive/1/archive/1/454944/100/0/threaded

来源: MISC

链接:http://www.sec-consult.com/272.html

来源: typo3.org

链接:http://typo3.org/news-single-view/?tx_newsimporter_pi1%5BshowItem%5D=0&cHash=e4a40a11a9

来源: MLIST

名称: [TYPO3-announce] 20061220 TYPO3 Security Bulletin TYPO3-20061220-1: Remote Command Execution in TYPO3

链接:http://lists.netfielders.de/pipermail/typo3-announce/2006/000046.html

来源: MLIST

名称: [TYPO3-announce] 20061219 Pre-announcement for important security update

链接:http://lists.netfielders.de/pipermail/typo3-announce/2006/000045.html

来源: SREASON

名称: 2056

链接:http://securityreason.com/securityalert/2056

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享