{"id":"GHSA-3cqw-pxgr-jhrm","summary":"TYPO3 Backend Command Injection via Shell Metacharacters in Uploaded File Name","details":"The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2, when the DAM extension or ftp upload is enabled, allows remote authenticated users to execute arbitrary commands via shell metacharacters in a filename.","aliases":["CVE-2009-3631"],"modified":"2024-02-08T21:58:59.279880Z","published":"2022-05-02T03:46:56Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-02-08T21:38:01Z","nvd_published_at":"2009-11-02T15:30:00Z","cwe_ids":["CWE-94"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2009-3631"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53923"},{"type":"PACKAGE","url":"https://github.com/TYPO3-CMS/backend"},{"type":"WEB","url":"https://web.archive.org/web/20101223093042/http://www.securityfocus.com/bid/36801"},{"type":"WEB","url":"http://marc.info/?l=oss-security&m=125632856206736&w=2"},{"type":"WEB","url":"http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-016"}],"affected":[{"package":{"name":"typo3/cms-backend","ecosystem":"Packagist","purl":"pkg:composer/typo3/cms-backend"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"4.0.13"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-3cqw-pxgr-jhrm/GHSA-3cqw-pxgr-jhrm.json"}},{"package":{"name":"typo3/cms-backend","ecosystem":"Packagist","purl":"pkg:composer/typo3/cms-backend"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.1.0"},{"fixed":"4.1.13"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-3cqw-pxgr-jhrm/GHSA-3cqw-pxgr-jhrm.json"}},{"package":{"name":"typo3/cms-backend","ecosystem":"Packagist","purl":"pkg:composer/typo3/cms-backend"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.2.0"},{"fixed":"4.2.10"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-3cqw-pxgr-jhrm/GHSA-3cqw-pxgr-jhrm.json"}},{"package":{"name":"typo3/cms-backend","ecosystem":"Packagist","purl":"pkg:composer/typo3/cms-backend"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.3alpha1"},{"fixed":"4.3beta2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-3cqw-pxgr-jhrm/GHSA-3cqw-pxgr-jhrm.json"}}],"schema_version":"1.9.0"}