{"id":"GHSA-f35p-hcwf-9f9f","summary":"TYPO3 Unrestricted File Upload vulnerability","details":"TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which allows remote attackers to bypass security restrictions and upload configuration files such as .htaccess, or conduct file upload attacks using multiple extensions.","aliases":["CVE-2008-2717"],"modified":"2024-02-09T16:56:40.618073Z","published":"2022-05-01T23:52:38Z","database_specific":{"github_reviewed_at":"2024-02-09T16:34:40Z","nvd_published_at":"2008-06-16T22:41:00Z","cwe_ids":["CWE-434"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2008-2717"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42988"},{"type":"PACKAGE","url":"https://github.com/TYPO3-CMS/core"},{"type":"WEB","url":"https://web.archive.org/web/20080815050856/http://securityreason.com/securityalert/3945"},{"type":"WEB","url":"https://web.archive.org/web/20081201212626/http://secunia.com/advisories/30619"},{"type":"WEB","url":"https://web.archive.org/web/20081206030529/http://secunia.com/advisories/30660"},{"type":"WEB","url":"https://web.archive.org/web/20200228131005/http://www.securityfocus.com/bid/29657"},{"type":"WEB","url":"https://web.archive.org/web/20201208012148/http://www.securityfocus.com/archive/1/493270/100/0/threaded"},{"type":"WEB","url":"http://buzz.typo3.org/teams/security/article/advice-on-core-security-issue-regarding-filedenypattern"},{"type":"WEB","url":"http://typo3.org/teams/security/security-bulletins/typo3-20080611-1"},{"type":"WEB","url":"http://www.debian.org/security/2008/dsa-1596"}],"affected":[{"package":{"name":"typo3/cms-core","ecosystem":"Packagist","purl":"pkg:composer/typo3/cms-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0"},{"fixed":"4.0.9"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-f35p-hcwf-9f9f/GHSA-f35p-hcwf-9f9f.json"}},{"package":{"name":"typo3/cms-core","ecosystem":"Packagist","purl":"pkg:composer/typo3/cms-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.1.0"},{"fixed":"4.1.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-f35p-hcwf-9f9f/GHSA-f35p-hcwf-9f9f.json"}},{"package":{"name":"typo3/cms-core","ecosystem":"Packagist","purl":"pkg:composer/typo3/cms-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.2.0"},{"fixed":"4.2.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-f35p-hcwf-9f9f/GHSA-f35p-hcwf-9f9f.json"}}],"schema_version":"1.9.0"}