Candidate: CVE-2010-1153 PublicDate: 2010-04-20 19:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1153 http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-008/ Description: PHP remote file inclusion vulnerability in the autoloader in TYPO3 4.3.x before 4.3.3 allows remote attackers to execute arbitrary PHP code via a URL in an input field associated with the className variable. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_typo3-src: upstream_typo3-src: released (4.3.3) dapper_typo3-src: ignored (reached end-of-life) hardy_typo3-src: ignored (reached end-of-life) intrepid_typo3-src: needs-triage (reached end-of-life) jaunty_typo3-src: ignored (reached end-of-life) karmic_typo3-src: ignored (reached end-of-life) lucid_typo3-src: ignored (reached end-of-life) maverick_typo3-src: not-affected (4.3.3-2) natty_typo3-src: not-affected (4.3.3-2) oneiric_typo3-src: not-affected (4.3.3-2) precise_typo3-src: not-affected (4.3.3-2) quantal_typo3-src: not-affected (4.3.3-2) raring_typo3-src: not-affected (4.3.3-2) saucy_typo3-src: not-affected (4.3.3-2) devel_typo3-src: not-affected (4.3.3-2)