« Volver al listado

CVE-2013-4250

Estado: ModificadaMedia (6.5)—

The (1) file upload component and (2) File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.3 do not properly check file extensions, which allow remote authenticated editors to execute arbitrary PHP code by uploading a .php file.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-4250",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-05-20T14:55:04.147",
  "references": [
    {
      "url": "https://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2013-002/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2013-002/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The (1) file upload component and (2) File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.3 do not properly check file extensions, which allow remote authenticated editors to execute arbitrary PHP code by uploading a .php file."
    },
    {
      "lang": "es",
      "value": "El (1) componente de carga de archivos y (2) la Capa de Abstracción de Archivo (FAL) en TYPO3 versiones 6.0.x anteriores a 6.0.8 y versiones 6.1.x anteriores a 6.1.3, no comprueba apropiadamente las extensiones de archivo, que le permiten a editores autenticados remotos ejecutar código PHP arbitrario mediante la carga de un archivo .php."
    }
  ],
  "lastModified": "2026-06-16T23:56:53.697",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:typo3:typo3:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "84C095F8-000A-4A8D-81DE-047810345A15"
            },
            {
              "criteria": "cpe:2.3:a:typo3:typo3:6.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "976AAF6F-BF03-40B7-B7D2-22101BD857D7"
            },
            {
              "criteria": "cpe:2.3:a:typo3:typo3:6.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6E98D0D9-D9AE-44F7-8233-F92EB330B152"
            },
            {
              "criteria": "cpe:2.3:a:typo3:typo3:6.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "36EA784A-7C3A-41DA-B444-D01E3BC144BB"
            },
            {
              "criteria": "cpe:2.3:a:typo3:typo3:6.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7294AA8B-0CD3-47A2-91DC-A882F7F3BDFC"
            },
            {
              "criteria": "cpe:2.3:a:typo3:typo3:6.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4D28DD85-FBB3-4DD4-B525-7AFD32BE55F6"
            },
            {
              "criteria": "cpe:2.3:a:typo3:typo3:6.0.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "80C21E07-5083-4C86-AA9D-FCB73F636060"
            },
            {
              "criteria": "cpe:2.3:a:typo3:typo3:6.0.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5DAE1BB4-2DBD-489E-B3F9-88CF414EAC2C"
            },
            {
              "criteria": "cpe:2.3:a:typo3:typo3:6.0.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A862C28E-B1B9-4541-A559-D0BD16E575B4"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:typo3:typo3:6.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C140F242-CF7C-4CB6-A358-5C8DB0F26DAA"
            },
            {
              "criteria": "cpe:2.3:a:typo3:typo3:6.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "81EAC0BA-B6AC-42BA-AEEE-946E1FBD770B"
            },
            {
              "criteria": "cpe:2.3:a:typo3:typo3:6.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AD31180A-8BD6-49AC-A758-5FA4C9A7B4C8"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}