Description
The Indexed Search Engine (indexed_search) system extension in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote attackers to execute arbitrary commands via a crafted filename containing shell metacharacters, which is not properly handled by the command-line indexer.
Remediation
References
Related Vulnerabilities
MySQL CVE-2018-2767 Vulnerability (CVE-2018-2767)
WordPress Plugin Student Result or Employee Database Security Bypass (1.6.3)
OpenSSL Cryptographic Issues Vulnerability (CVE-2014-3568)
Joomla! Core 3.x.x Open Redirect (3.0.0 - 3.9.20)
WordPress Plugin Tigris for Salesforce PHP Object Injection (1.1.3)