The jumpUrl (aka access tracking) implementation in tslib/class.tslib_fe.php in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 does not properly compare certain hash values during access-control decisions, which allows remote attackers to read arbitrary files via unspecified vectors.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/43786 | vdb entry |
http://www.exploit-db.com/exploits/15856 | exploit |
http://www.debian.org/security/2010/dsa-2121 | vendor advisory |
http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-020/ | patch vendor advisory |
http://blog.nibblesec.org/2010/12/typo3-sa-2010-020-typo3-sa-2010-022.html |