Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.9 and 6.1.x before 6.1.4 does not properly check permissions, which allows remote authenticated users to create or read arbitrary files via a crafted URL.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
TYPO3 文件处理安全绕过漏洞
Vulnerability Description
TYPO3是瑞士TYPO3协会维护的一套免费开源的内容管理系统(框架)(CMS/CMF)。 TYPO3 6.0.9之前的6.0.x版本和6.1.4之前的6.1.x版本中的File Abstraction Layer (FAL)存在安全漏洞,该漏洞源于程序没有正确检查权限。远程攻击者可借助特制的URL利用该漏洞创建或读取任意文件。
CVSS Information
N/A
Vulnerability Type
N/A