CVE-2009-3635

critical

Description

The Install Tool subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote attackers to gain access by using only the password's md5 hash as a credential.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/53928

http://www.vupen.com/english/advisories/2009/3009

http://www.securityfocus.com/bid/36801

http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-016/

http://secunia.com/advisories/37122

http://marc.info/?l=oss-security&m=125632856206736&w=2

Details

Source: Mitre, NVD

Published: 2009-11-02

Updated: 2024-11-21

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Severity: Critical