Description
The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2, when the DAM extension or ftp upload is enabled, allows remote authenticated users to execute arbitrary commands via shell metacharacters in a filename.
Remediation
References
Related Vulnerabilities
WordPress Plugin Google XML Sitemap for Images Cross-Site Request Forgery (2.1.3)
Internet Information Services Improper Input Validation Vulnerability (CVE-2009-4445)
WordPress Plugin Best Image Gallery & Responsive Photo Gallery-FooGallery Security Bypass (1.6.15)
WordPress Plugin Login No Captcha reCAPTCHA Security Bypass (1.4.1)