view_help.php in the backend help system in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote authenticated backend users to unserialize arbitrary objects and possibly execute arbitrary PHP code via an unspecified parameter, related to a "missing signature (HMAC)."
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2012-09-05 16:55
Updated : 2017-08-28 18:31
NVD link : CVE-2012-3527
Mitre link : CVE-2012-3527
JSON object : View
CWE
CWE-310
Cryptographic Issues
Products Affected
typo3
- typo3