CVE-2006-0327

Publication date 21 January 2006

Last updated 17 July 2025


Ubuntu priority

Description

TYPO3 3.7.1 allows remote attackers to obtain sensitive information via a direct request to (1) thumbs.php, (2) showpic.php, or (3) tables.php, which causes them to incorrectly define a variable and reveal the path in an error message when a require function call fails.

Status

Package Ubuntu Release Status
typo3-src 9.10 karmic
Fixed 4.0.4+debian-2
9.04 jaunty
Fixed 4.0.4+debian-2
8.10 intrepid
Fixed 4.0.4+debian-2
8.04 LTS hardy
Fixed 4.0.4+debian-2
7.10 gutsy
Fixed 4.0.4+debian-2
7.04 feisty
Fixed 4.0.4+debian-2
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life