Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2006-6690

rtehtmlarea/pi1/class.tx_rtehtmlarea_pi1.php in Typo3 4.0.0 through 4.0.3, 3.7 and 3.8 with the rtehtmlarea extension, and 4.1 beta allows remote authenticated users to execute arbitrary commands via shell metacharacters in the userUid parameter to rtehtmlarea/htmlarea/plugins/SpellChecker/spell-check-logic.php, and possibly another vector.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.162
EPSS Ranking 94.5%
CVSS Severity
CVSS v2 Score 7.5
References
Products affected by CVE-2006-6690
  • Typo3 » Typo3 » Version: 3.7.0
    cpe:2.3:a:typo3:typo3:3.7.0
  • Typo3 » Typo3 » Version: 3.8
    cpe:2.3:a:typo3:typo3:3.8
  • Typo3 » Typo3 » Version: 4.0
    cpe:2.3:a:typo3:typo3:4.0
  • Typo3 » Typo3 » Version: 4.0.1
    cpe:2.3:a:typo3:typo3:4.0.1
  • Typo3 » Typo3 » Version: 4.0.2
    cpe:2.3:a:typo3:typo3:4.0.2
  • Typo3 » Typo3 » Version: 4.0.3
    cpe:2.3:a:typo3:typo3:4.0.3


Contact Us

Shodan ® - All rights reserved