Looking for the vulnerability index of Invicti's legacy products?
TYPO3 Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-3942) - Vulnerability Database

TYPO3 Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-3942)

Description

The Color Picker Wizard component in TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, and 6.1.0 before 6.1.9 allows remote authenticated editors to execute arbitrary PHP code via a serialized PHP object.

References

Related Vulnerabilities