Description
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains an insecure default value of the variable fileDenyPattern which could allow remote attackers to execute arbitrary code on the backend.
Remediation
References
Related Vulnerabilities
WordPress Plugin Subscribe to Comments Unsubscribe Challenge Information Disclosure (2.0.2)
Drupal Core 9.3.x Security Bypass (9.3.0 - 9.3.13)
Oracle Database Server CVE-2014-4300 Vulnerability (CVE-2014-4300)
PrestaShop URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2020-5270)