CVE-2012-1607 describes an information disclosure vulnerability in the Command Line Interface (CLI) script of TYPO3 versions 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0. This flaw allows unauthenticated remote attackers to obtain the database name through a direct request to the CLI script. With a CVSS score of 5.0, this vulnerability is of medium severity, requiring no authentication or complex attack vectors (AV:N/AC:L/Au:N) to achieve partial confidentiality impact (C:P). The EPSS score is very low, indicating a minimal probability of exploitation. There is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion is minimal, with only one mention, and there is no media coverage, suggesting low attention and impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.4CPE matchmatch criteria | cpe:2.3:a:typo3:typo3:4.4:*:*:*:*:*:*:* | ||
4.4.0CPE matchmatch criteria | cpe:2.3:a:typo3:typo3:4.4.0:*:*:*:*:*:*:* | ||
4.4.1CPE matchmatch criteria | cpe:2.3:a:typo3:typo3:4.4.1:*:*:*:*:*:*:* | ||
4.4.2CPE matchmatch criteria | cpe:2.3:a:typo3:typo3:4.4.2:*:*:*:*:*:*:* | ||
4.4.3CPE matchmatch criteria | cpe:2.3:a:typo3:typo3:4.4.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.