Moderate severityNVD Advisory· Published May 30, 2012· Updated Apr 29, 2026
CVE-2010-5099
CVE-2010-5099
Description
The fileDenyPattern functionality in the PHP file inclusion protection API in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 does not properly filter file types, which allows remote attackers to bypass intended access restrictions and access arbitrary PHP files, as demonstrated using path traversal sequences with %00 null bytes and CVE-2010-3714 to read the TYPO3 encryption key from localconf.php.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
typo3/cmsPackagist | >= 4.2.0, < 4.2.16 | 4.2.16 |
typo3/cmsPackagist | >= 4.3.0, < 4.3.9 | 4.3.9 |
typo3/cmsPackagist | >= 4.4.0, < 4.4.5 | 4.4.5 |
Affected products
30cpe:2.3:a:typo3:typo3:4.2.0:*:*:*:*:*:*:*+ 29 more
- cpe:2.3:a:typo3:typo3:4.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.2.10:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.2.11:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.2.12:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.2.13:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.2.14:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.2.15:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.2.5:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.2.6:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.2.7:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.2.8:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.2.9:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.3.3:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.3.4:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.3.5:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.3.6:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.3.7:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.3.8:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.4.3:*:*:*:*:*:*:*
- cpe:2.3:a:typo3:typo3:4.4.4:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
12- blog.nibblesec.org/2010/12/typo3-sa-2010-020-typo3-sa-2010-022.htmlnvdExploitWEB
- www.exploit-db.com/exploits/15856nvdExploitWEB
- secunia.com/advisories/35770nvdVendor Advisory
- typo3.org/teams/security/security-bulletins/typo3-core/typo3-sa-2010-022/nvdVendor Advisory
- github.com/advisories/GHSA-66j3-66cp-6c2mghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2010-5099ghsaADVISORY
- www.openwall.com/lists/oss-security/2011/01/13/2nvdWEB
- www.openwall.com/lists/oss-security/2012/05/10/7nvdWEB
- www.openwall.com/lists/oss-security/2012/05/11/3nvdWEB
- www.openwall.com/lists/oss-security/2012/05/12/5nvdWEB
- exchange.xforce.ibmcloud.com/vulnerabilities/64180nvdWEB
- web.archive.org/web/20120801235059/http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-sa-2010-022ghsaWEB
News mentions
0No linked articles in our index yet.