Actions
Bug #23675
closedIt is (still) possible to download arbitrary files through the jumpurl feature
Status:
Closed
Priority:
Must have
Assignee:
-
Category:
Communication
Target version:
-
Start date:
2010-10-05
Due date:
% Done:
0%
Estimated time:
TYPO3 Version:
4.2
PHP Version:
5.2
Tags:
Complexity:
Is Regression:
Sprint Focus:
Description
Quote from Gregor Kopf
===========
I have identified two issues in Typo3, which can be combined to evade
the juSecure/juHash validation and therefore to download arbitrary
files from the server. The details are described below.
1) Non-typesafe comparison
[REMOVED]
2) Short hash value
[REMOVED]
OTRS: 2010100410000034
Reporter: Gregor Kopf
(issue imported from #M15898)
Files
Updated by Helmut Hummel about 14 years ago
Exploit Code:
=====================
[REMOVED]
====================
[REMOVED]
Updated by Helmut Hummel about 14 years ago
added t3lib_div::resolveBackPath before creating the absolute filename for enhanced compatibility to the current behaviour in th v2 patches
Updated by Marcus Krause about 14 years ago
+1 by reading v2
+1 by testing v2 on 4-2, 4-3 and 4-4
Actions