7.5

CVE-2014-3947

Unrestricted file upload vulnerability in the powermail extension before 1.6.11 and 2.x before 2.0.14 for TYPO3 allows remote attackers to execute arbitrary code by uploading a file with a crafted extension, then accessing it via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Alex Kellner ≫ Powermail SwPlatform typo3 Version <= 1.6.10
Alex Kellner ≫ Powermail Version 2.0.0 SwPlatform typo3
Alex Kellner ≫ Powermail Version 2.0.1 SwPlatform typo3
Alex Kellner ≫ Powermail Version 2.0.2 SwPlatform typo3
Alex Kellner ≫ Powermail Version 2.0.3 SwPlatform typo3
Alex Kellner ≫ Powermail Version 2.0.4 SwPlatform typo3
Alex Kellner ≫ Powermail Version 2.0.5 SwPlatform typo3
Alex Kellner ≫ Powermail Version 2.0.6 SwPlatform typo3
Alex Kellner ≫ Powermail Version 2.0.7 SwPlatform typo3
Alex Kellner ≫ Powermail Version 2.0.8 SwPlatform typo3
Alex Kellner ≫ Powermail Version 2.0.9 SwPlatform typo3
Alex Kellner ≫ Powermail Version 2.0.10 SwPlatform typo3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.33% 0.813
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

http://typo3.org/extensions/repository/view/powermail
http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2014-007/