fkie_cve-2009-3819
Vulnerability from fkie_nvd
Published
2009-10-28 10:30
Modified
2025-04-09 00:30
Severity ?
Summary
Unspecified vulnerability in the Random Images (maag_randomimage) extension 1.6.4 and earlier for TYPO3 allows remote attackers to execute arbitrary shell commands via unspecified vectors.



{
  "configurations": [
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:typo3:typo3:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "5F1C59B0-CDF2-4F9A-88C7-61E8F18590DB",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "18A420CC-4277-48B2-9A66-6DDAC9044EF1",
              "versionEndIncluding": "1.6.4",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:0.0.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "95424F48-8382-4CB2-8646-B4728DCE69FE",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:0.2.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "170E0D7E-9604-4A0C-829E-BCC4ACBC060F",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.0.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "283B2C4F-B621-439F-803E-65BA70628662",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.1.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "0ED37F65-7DC9-4BDE-B263-A438D17D8DBC",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.1.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "EC9A56F4-8AA3-4D34-8AB1-57598BE75046",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.1.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "D49B8DB2-64A4-41FE-B58C-B4306272C30B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.1.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "A02063A7-37EC-4EE4-B125-98D217B7E9D0",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.1.6:*:*:*:*:*:*:*",
              "matchCriteriaId": "EEE27643-45FF-4CF0-B371-E44555F19E61",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.2.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "48BAC3B6-293E-4069-8F1C-C6D0EEDAC050",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.2.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "7071023B-6A06-4BF9-A09E-7780D0E7492E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.2.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "63728811-B095-4D78-837F-48090556FA1E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.2.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "EA50B1AE-62BD-47A9-B5E5-B23FF8BC66A2",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.2.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "1A6C1383-D6BF-4974-BCB2-1508B676F1C4",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.2.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "C0264710-9DED-4CF7-9853-4216CEE4FF58",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.2.6:*:*:*:*:*:*:*",
              "matchCriteriaId": "A038C7D8-B875-4657-A178-3741240835B8",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.2.7:*:*:*:*:*:*:*",
              "matchCriteriaId": "1D1526A5-9A7D-4EC7-870E-5E14736E5401",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.2.8:*:*:*:*:*:*:*",
              "matchCriteriaId": "652CE8EA-395C-4CF9-894F-D65FA8BD9C27",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.2.9:*:*:*:*:*:*:*",
              "matchCriteriaId": "86D7BFCD-A90A-4FAA-84E6-82D4DA2F668F",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.2.10:*:*:*:*:*:*:*",
              "matchCriteriaId": "7CD1EF4C-A164-47FB-9CC3-1FA8C2053C54",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.2.11:*:*:*:*:*:*:*",
              "matchCriteriaId": "7C23F763-5691-42F1-97E7-6EF90E5C627D",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.2.12:*:*:*:*:*:*:*",
              "matchCriteriaId": "0E85939C-2F7D-4651-8A14-D223A099EBC3",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.2.13:*:*:*:*:*:*:*",
              "matchCriteriaId": "78C38576-EC47-434D-8C1B-0E9188EA7A7C",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.2.14:*:*:*:*:*:*:*",
              "matchCriteriaId": "9B80DE17-8604-4F20-BA02-012A636D7D1C",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.3.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "28B7DC02-697C-4130-ABBA-75BE2716D491",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.3.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "D50E566B-D9C0-402B-B83D-69DE2247EF0B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.4.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "A16B2B61-2D71-46C9-B38E-32403E39A1D2",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.4.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "F8825D1E-2694-4BF4-A58F-C625C0D0B453",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.5.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "D0A2B8DE-4516-4F91-A56E-E621F76C3F00",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.5.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "5D6F8600-1F08-460E-B021-77F8D3209FB6",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.5.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "793D2B07-3B1D-4E47-9086-A5D5DEB9B1C8",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.5.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "D37AE0A4-21BA-47FD-BD83-3A5E9B93969B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.5.6:*:*:*:*:*:*:*",
              "matchCriteriaId": "DFDA7AC1-54D1-4F24-A131-221AD172AF3B",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.5.7:*:*:*:*:*:*:*",
              "matchCriteriaId": "BDDAE991-4697-4981-ACF0-1A6B512A5B7D",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.5.8:*:*:*:*:*:*:*",
              "matchCriteriaId": "6FB2AD0D-44BE-4F38-9290-CA4DD7FC373A",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.6.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "E77F4DE7-F986-44F4-A9C8-AE72D6D9A353",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.6.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "13C5203A-0BA9-4091-BE77-0297A16502BC",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.6.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "C4AF0510-4807-4554-A6CE-AB3D2018CED1",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:urs_maag:maag_randomimage:1.6.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "229CC6E7-4B2A-4C28-A820-68DDCC23D727",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "cveTags": [],
  "descriptions": [
    {
      "lang": "en",
      "value": "Unspecified vulnerability in the Random Images (maag_randomimage) extension 1.6.4 and earlier for TYPO3 allows remote attackers to execute arbitrary shell commands via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad no especificada en the Random Images (maag_randomimage) extension v1.6.4 y anteriores para TYPO3 permite a atacantes remotos ejecutar comandos de shell a trav\u00e9s de vectores no especificados."
    }
  ],
  "id": "CVE-2009-3819",
  "lastModified": "2025-04-09T00:30:58.490",
  "metrics": {
    "cvssMetricV2": [
      {
        "acInsufInfo": false,
        "baseSeverity": "HIGH",
        "cvssData": {
          "accessComplexity": "LOW",
          "accessVector": "NETWORK",
          "authentication": "NONE",
          "availabilityImpact": "COMPLETE",
          "baseScore": 10.0,
          "confidentialityImpact": "COMPLETE",
          "integrityImpact": "COMPLETE",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "version": "2.0"
        },
        "exploitabilityScore": 10.0,
        "impactScore": 10.0,
        "obtainAllPrivilege": false,
        "obtainOtherPrivilege": false,
        "obtainUserPrivilege": false,
        "source": "nvd@nist.gov",
        "type": "Primary",
        "userInteractionRequired": false
      }
    ]
  },
  "published": "2009-10-28T10:30:00.797",
  "references": [
    {
      "source": "cve@mitre.org",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://secunia.com/advisories/37095"
    },
    {
      "source": "cve@mitre.org",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "url": "http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-014/"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://secunia.com/advisories/37095"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "url": "http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-014/"
    }
  ],
  "sourceIdentifier": "cve@mitre.org",
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ],
      "source": "nvd@nist.gov",
      "type": "Primary"
    }
  ]
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…