Arbitrary PHP Code Execution in TYPO3 File Abstraction Layer (FAL)

Arbitrary PHP Code Execution in TYPO3 File Abstraction Layer (FAL)

CVE-2013-4321 · MEDIUM Severity

AV:N/AC:L/AU:S/C:P/I:P/A:P

The File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.4 allows remote authenticated editors to execute arbitrary PHP code via unspecified characters in the file extension when renaming a file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4250.

Learn more about our Web Application Penetration Testing UK.