CVE-2014-6235
TYPO3 Extension ke DomPDF - Remote Code Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Unspecified vulnerability in the ke DomPDF extension before 0.0.5 for TYPO3 allows remote attackers to execute arbitrary code via unknown vectors.
Vulnerabilidad no especificada en la extensión ke DomPDF anterior a 0.0.5 para TYPO3 permite a atacantes remotos ejecutar código arbitrario a través de vectores desconocidos.
The TYPO3 extension ke_dompdf contains a version of the dompdf library including all files originally supplied with it. This includes an examples page, which contains different examples for HTML-entities rendered as a PDF. This page also allows users to enter their own HTML code into a text box to be rendered by the webserver using dompdf. dompdf also supports rendering of PHP files and the examples page also accepts PHP code tags, which are then executed and rendered into a PDF on the server. Since those files are not protected in the TYPO3 extension directory, anyone can access this URL and execute arbitrary PHP code on the system. This behavior was already fixed in the dompdf library, but the typo3 extension ke_dompdf supplies an old version of the library that still allows the execution of arbitrary PHP code. Versions 0.0.3 and below are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-09-04 CVE Reserved
- 2014-09-11 CVE Published
- 2014-12-02 First Exploit
- 2023-10-06 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/69563 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/95706 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/35443 | 2014-12-02 |
URL | Date | SRC |
---|---|---|
http://typo3.org/extensions/repository/view/ke_dompdf | 2017-09-08 | |
http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2014-010 | 2017-09-08 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Kennziffer Search vendor "Kennziffer" | Ke Dompdf Search vendor "Kennziffer" for product "Ke Dompdf" | <= 0.0.3 Search vendor "Kennziffer" for product "Ke Dompdf" and version " <= 0.0.3" | typo3 |
Affected
|