CVE-2006-6690
N/A
N/A
Summary
rtehtmlarea/pi1/class.tx_rtehtmlarea_pi1.php in Typo3 4.0.0 through 4.0.3, 3.7 and 3.8 with the rtehtmlarea extension, and 4.1 beta allows remote authenticated users to execute arbitrary commands via shell metacharacters in the userUid parameter to rtehtmlarea/htmlarea/plugins/SpellChecker/spell-check-logic.php, and possibly another vector.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.securityfocus.com/archive/1/454944/100/0/threaded
- http://secunia.com/advisories/23466
- http://www.sec-consult.com/272.html
- http://lists.netfielders.de/pipermail/typo3-announce/2006/000045.html
- http://securitytracker.com/id?1017428
- http://securityreason.com/securityalert/2056
- http://lists.netfielders.de/pipermail/typo3-announce/2006/000046.html
- http://secunia.com/advisories/23446
- http://typo3.org/news-single-view/?tx_newsimporter_pi1%5BshowItem%5D=0&cHash=e4a40a11a9
- http://www.vupen.com/english/advisories/2006/5094
- http://www.securityfocus.com/bid/21680
References
- http://www.securityfocus.com/archive/1/454944/100/0/threaded
- http://secunia.com/advisories/23466
- http://www.sec-consult.com/272.html
- http://lists.netfielders.de/pipermail/typo3-announce/2006/000045.html
- http://securitytracker.com/id?1017428
- http://securityreason.com/securityalert/2056
- http://lists.netfielders.de/pipermail/typo3-announce/2006/000046.html
- http://secunia.com/advisories/23446
- http://typo3.org/news-single-view/?tx_newsimporter_pi1%5BshowItem%5D=0&cHash=e4a40a11a9
- http://www.vupen.com/english/advisories/2006/5094
- http://www.securityfocus.com/bid/21680
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.