Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
rtehtmlarea/pi1/class.tx_rtehtmlarea_pi1.php in Typo3 4.0.0 through 4.0.3, 3.7 and 3.8 with the rtehtmlarea extension, and 4.1 beta allows remote authenticated users to execute arbitrary commands via shell metacharacters in the userUid parameter to rtehtmlarea/htmlarea/plugins/SpellChecker/spell-check-logic.php, and possibly another vector.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Typo3 'Class.TX_RTEHTMLArea_PI1.PHP'多个远程命令执行漏洞
Vulnerability Description
Typo3 4.0.0至4.0.3、带有rtehtmlarea扩展的3.7和3.8版,以及4.1 beta版中的rtehtmlarea/pi1/class.tx_rtehtmlarea_pi1.php存在远程命令执行漏洞。远程认证用户通过传给rtehtmlarea/htmlarea/plugins/SpellChecker/spell-check-logic.php的userUid参数中的shell元字符,以及可能的其他向量,来执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A