CVE-2009-0815
TYPO3 <4.0.12-4.3alpha1 - Info Disclosure
Title source: llmDescription
The jumpUrl mechanism in class.tslib_fe.php in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 before 4.2.6, and 4.3alpha1 leaks a hash secret (juHash) in an error message, which allows remote attackers to read arbitrary files by including the hash in a request.
Exploits (2)
metasploit
WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/typo3_sa_2009_002.rb
References (4)
Scores
EPSS
0.4980
EPSS Percentile
97.8%
Details
CWE
CWE-200
Status
published
Products (25)
typo3/cms
3.3 - 4.0.12Packagist
typo3/typo3
3.3.x
typo3/typo3
3.5.x
typo3/typo3
3.6.x
typo3/typo3
3.7.x
typo3/typo3
3.8.x
typo3/typo3
4.0
typo3/typo3
4.1
typo3/typo3
4.1.0
typo3/typo3
4.1.2
... and 15 more
Published
Mar 05, 2009
Tracked Since
Feb 18, 2026