Looking for the vulnerability index of Invicti's legacy products?
TYPO3 Improper Input Validation Vulnerability (CVE-2013-4250) - Vulnerability Database

TYPO3 Improper Input Validation Vulnerability (CVE-2013-4250)

Description

The (1) file upload component and (2) File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.3 do not properly check file extensions, which allow remote authenticated editors to execute arbitrary PHP code by uploading a .php file.

References

Related Vulnerabilities