AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2008-2717

MEDIUM · CVSS 6.5 EPSS 3.02%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2008-06-16 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2008-2717
Severity
MEDIUM
CVSS
6.5
EPSS
3.02%
Apache

Original NVD Description

TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which allows remote attackers to bypass security restrictions and upload configuration files such as .htaccess, or conduct file upload attacks using multiple extensions.