CVE-2010-5099
TYPO3 <4.2.16, 4.3.9, 4.4.5 - Path Traversal
Title source: llmDescription
The fileDenyPattern functionality in the PHP file inclusion protection API in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 does not properly filter file types, which allows remote attackers to bypass intended access restrictions and access arbitrary PHP files, as demonstrated using path traversal sequences with %00 null bytes and CVE-2010-3714 to read the TYPO3 encryption key from localconf.php.
Exploits (1)
References (9)
Scores
EPSS
0.0525
EPSS Percentile
90.0%
Details
CWE
CWE-20
Status
published
Products (31)
typo3/cms
4.2.0 - 4.2.16Packagist
typo3/typo3
4.2.0
typo3/typo3
4.2.1
typo3/typo3
4.2.2
typo3/typo3
4.2.3
typo3/typo3
4.2.4
typo3/typo3
4.2.5
typo3/typo3
4.2.6
typo3/typo3
4.2.7
typo3/typo3
4.2.8
... and 21 more
Published
May 30, 2012
Tracked Since
Feb 18, 2026