CVE-2006-0327

TYPO3 3.7.1 allows remote attackers to obtain sensitive information via a direct request to (1) thumbs.php, (2) showpic.php, or (3) tables.php, which causes them to incorrectly define a variable and reveal the path in an error message when a require function call fails.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:typo3:typo3:3.7.1:*:*:*:*:*:*:*
cpe:2.3:a:typo3:typo3:3.8.1:*:*:*:*:*:*:*

History

21 Nov 2024, 00:06

Type Values Removed Values Added
References () http://bugs.typo3.org/view.php?id=2248 - () http://bugs.typo3.org/view.php?id=2248 -
References () http://secunia.com/advisories/18546 - Vendor Advisory () http://secunia.com/advisories/18546 - Vendor Advisory
References () http://securityreason.com/securityalert/361 - () http://securityreason.com/securityalert/361 -
References () http://www.irmplc.com/advisory015.htm - Exploit, Vendor Advisory () http://www.irmplc.com/advisory015.htm - Exploit, Vendor Advisory
References () http://www.osvdb.org/22665 - () http://www.osvdb.org/22665 -
References () http://www.osvdb.org/22666 - () http://www.osvdb.org/22666 -
References () http://www.osvdb.org/22667 - () http://www.osvdb.org/22667 -
References () http://www.securityfocus.com/archive/1/422360/100/0/threaded - () http://www.securityfocus.com/archive/1/422360/100/0/threaded -
References () http://www.securityfocus.com/archive/1/422390/100/0/threaded - () http://www.securityfocus.com/archive/1/422390/100/0/threaded -
References () http://www.vupen.com/english/advisories/2006/0269 - () http://www.vupen.com/english/advisories/2006/0269 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/24244 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/24244 -

Information

Published : 2006-01-21 00:03

Updated : 2024-11-21 00:06


NVD link : CVE-2006-0327

Mitre link : CVE-2006-0327

CVE.ORG link : CVE-2006-0327


JSON object : View

Products Affected

typo3

  • typo3