CVE-2013-4320

The File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.9 and 6.1.x before 6.1.4 does not properly check permissions, which allows remote authenticated users to create or read arbitrary files via a crafted URL.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:P/I:P/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 33%
VendorProductVersion
typo3typo3
6.1
typo3typo3
6.1.1
typo3typo3
6.1.2
typo3typo3
6.1.3
typo3typo3
6.0
typo3typo3
6.0.1
typo3typo3
6.0.2
typo3typo3
6.0.3
typo3typo3
6.0.4
typo3typo3
6.0.5
typo3typo3
6.0.6
typo3typo3
6.0.7
typo3typo3
6.0.8
𝑥
= Vulnerable software versions
Common Weakness Enumeration