Security Bulletins

Email header injection

Authors: , Category: TYPO3 Core February 21, 2007

A problem has been discovered where the internal form engine can be used for sending arbitrary mail headers, using it for purposes which it is not meant for.

Details

tip-a-friend

Authors: , Category: TYPO3 Extension September 02, 2006

A problem has been discovered with tip-a-friend being vulnerable to Cross-Site-Scripting (XSS)

Details