← All CVEs

CVE-2010-3714

high · 7.1

The jumpUrl (aka access tracking) implementation in tslib/class.tslib_fe.php in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 does not properly compare certain hash values during access-control decisions, which allows remote attackers to read arbitrary files via unspecified vectors.

7.1
CVSS
24.1%
EPSS (exploit prob.)
98th
EPSS percentile
2010-10-25
Published

AV:N/AC:M/Au:N/C:C/I:N/A:N

Weaknesses

CWE-264

Affected products

VendorProductAffected versions
typo3typo34.2.0
typo3typo34.2.1
typo3typo34.2.2
typo3typo34.2.3
typo3typo34.2.4
typo3typo34.2.5
typo3typo34.2.6
typo3typo34.2.7
typo3typo34.2.8
typo3typo34.2.9
typo3typo34.2.10
typo3typo34.2.11
typo3typo34.2.12
typo3typo34.2.13
typo3typo34.2.14
typo3typo34.3.0
typo3typo34.3.1
typo3typo34.3.2
typo3typo34.3.3
typo3typo34.3.4
typo3typo34.3.5
typo3typo34.3.6
typo3typo34.4
typo3typo34.4.1
typo3typo34.4.2
typo3typo34.4.3

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2010-3714