Login / Status
developer.Resource
Home . Teams . Security . Security Bulletins
Sponsors
hosted by punkt.deTYPO3 and Open Source MagazineAOE Media

TYPO3 Security Bulletins

This is a list of security bulletins which were released by the TYPO3 Security Team. If you think you have found a security problem in TYPO3 or one of the extensions or have any questions regarding these security bulletins, please contact the security team directly.

  • TYPO3-20080924-2

    It has been discovered that the extension freeCap CAPTCHA (sr_freecap) is vulnerable to Cross-Site Scripting.

  • TYPO3-20080924-1

    It has been discovered that the extension phpMyAdmin (phpmyadmin) is vulnerable to Cross-Site Scripting.

  • TYPO3-20080919-1

    Several vulnerabilities have been found in TYPO3 third party extensions.

  • TYPO3-20080916-1

    It has been discovered that the extension phpMyAdmin (phpmyadmin) is vulnerable to Code Execution.

  • TYPO3-20080701-4

    It has been discovered that the extension WEC Discussion Forum (wec_discussion) is open to multiple security issues.

  • TYPO3-20080701-3

    It has been discovered that the extension Send-A-Card (sr_sendcard) is open to multiple security issues.

  • TYPO3-20080701-2

    It has been discovered that the extension phpmyadmin is susceptible to Cross Site Scripting (XSS) attacks.

  • TYPO3-20080701-1

    Several vulnerabilities have been found in TYPO3 third party extensions.

  • TYPO3-20080619-1

    Several vulnerabilities have been found in TYPO3 third party extensions.

  • TYPO3-20080611-1

    It has been discovered that the default value of the TYPO3 configuration variable fileDenyPattern allows arbitrary code execution on Apache web servers. Besides that, the library fe_adminlib.inc allows Cross Site Scripting (XSS).

  • TYPO3-20080527-2

    It has been discovered that the extension "Library for Frontend plugins" (sg_zfelib) is susceptible to SQL Injections.

  • TYPO3-20080527-1

    It has been discovered that the extension "KJ: Image Lightbox v2" (kj_imagelightbox2) is susceptible to Cross Site Scripting (XSS) attacks.

  • TYPO3-20080515-2

    It has been discovered that the extension Frontend Filemanager (air_filemanager) is susceptible to Cross Site Scripting (XSS) attacks and allows Remote Code Execution.

  • TYPO3-20080515-1

    It has been discovered that the extension Frontend User Registration (sr_feuser_register) is susceptible to Cross Site Scripting (XSS) attacks and allows Remote Command Execution.

  • TYPO3-20080513-4

    It has been discovered that the extension Statistics (ke_stats) is vulnerable to Blind SQL Injection attacks. Also, a Cross Site Scripting issue has been found.

  • TYPO3-20080513-3

    It has been discovered that the extension Event Database (rlmp_eventdb) is susceptible to Cross Site Scripting (XSS) attacks.

  • TYPO3-20080513-2

    It has been discovered that the extension Questionaire (pbsurvey) is susceptible to Cross Site Scripting (XSS) attacks.

  • TYPO3-20080513-1

    It has been discovered that the extension wt_gallery is susceptible to Path Traversal and Cross Site Scripting (XSS) attacks. Besides that, it may disclose sensitive information.

  • TYPO3-20080505-2

    It has been discovered that the extension powermail is susceptible to Cross Site Scripting (XSS) attacks.

  • TYPO3-20080505-1

    It has been discovered that the extension MailformPlus (th_mailformplus) is susceptible to Cross Site Scripting (XSS) attacks and allows Remote Code Execution.

  • TYPO3-20080416-2

    It has been discovered that the extensions pmk_rssnewsexport and cm_rdfexport are vulnerable to SQL Injection attacks.

  • TYPO3-20080416-1

    It has been discovered that the extension de_phpot is vulnerable to multiple SQL Injection flaws and other types of security issues.

  • TYPO3-20071210-1

    It has been discovered that the system extension indexed_search is vulnerable to a SQL Injection flaw.

  • TYPO3-20070919-1

    It has been discovered that the extension mm_forum is vulnerable to multiple SQL Injection attacks and multiple XSS flaws alongside other vulnerabilities.

  • TYPO3-20070801-1

    It has been discovered that the extension ve_guestbook is vulnerable to SQL Injection attacks. Also, a Cross Site Scripting issue has been detected.

  • TYPO3-20070719-1

    Multiple TYPO3 extensions is affected by the third party tool PHPMailer, which is vulnerable to a remote shell command execution.

  • TYPO3-20070716-2

    An information disclosure issue has been found in the phpmyadmin extension of TYPO3 that may give access to phpinfo() information in special cases. The standalone version of phpmyadmin is not affected.

  • TYPO3-20070716-1

    It has been discovered that the extension faq is susceptible to cross site scripting (XSS) attacks, making it possible to execute arbitrary JavaScript.

  • TYPO3-20070712-1

    Multiple vulnerabilities has been found in the extension civserv: Incorrect handling of input from GET/POST-variables, and allowing an attacker to execute XSS and/or SQL Injection attacks.

  • TYPO3-20070710-1

    It has been discovered that the extension fechangepassword is open for a SQL injection when updating the password.

  • TYPO3-20070709-1

    It has been discovered that the extension ftpbrowser is doing incorrect authentication in some files, making it open for exploiting.

  • TYPO3-20070703-1

    Multiple vulnerabilities have been found in the third party extension "mysqldumper". Full read/write access to the connected database and other related issues.

  • TYPO3-20070612-1

    It has been discovered that the extension w4x_backup has several security related issues, which may disclosure confidential information.

  • TYPO3-20070608-1

    It has been discovered that the extensions macina_banners and its descendant ric_rotation are exposed to an SQL injection issue because they fail to properly sanitize user-supplied input.

  • TYPO3-20070221-1

    A problem has been discovered where the internal form engine can be used for sending arbitrary mail headers, using it for purposes which it is not meant for.

  • TYPO3-20070124-1

    A header injection problem has been found in the extension tipafriend

  • TYPO3-20061220-1

    A critical problem has been discovered in plugin class.tx_rtehtmlarea_pi1.php that is used for spell-checking in the rtehtmlarea extension.

  • TYPO3-20061205-1

    A problem has been discovered with thumbs.php providing access to unwanted files

  • TYPO3-20061010-1

    A problem has been discovered with fe_adminLib.inc bein vulnerable for Cross Site Scripting (XSS)

  • TYPO3-20060911-1

    A problem has been discovered with indexed search being vulnerable to Cross-Site-Scripting (XSS)

  • TYPO3-20060902-1

    A problem has been discovered with tip-a-friend being vulnerable to Cross-Site-Scripting (XSS)

  • TYPO3-20060512-1

    Two problems (path traversal and SQL injection) have been discovered in the extension dam_downloads

  • TYPO3-20060501-1

    A weakness in the display of forum messages of chc_forum has been discovered that may be used to execute arbitrary SQL

  • TYPO3-20051114-7

    Situations are imaginable where sensitive information gets stored in the fileadmin/_temp_/ directory. If misconfigured in your web server, this directory can be browsable and therefore expose that information.

  • TYPO3-20051114-6

    Under special circumstances, setting config.baseURL (see typo3.org/documentation/document-library/doc_core_tsref/quot_CONFIG_quot/ ) to a numeric value ("1") could be used to spoof a malicious baseURL into your TYPO3 cache. It has now been decided to technically prevent this misconfiguration.

  • TYPO3-20051114-5

    For convenience, the TYPO3 Install Tool provides a button sets the "encryptionKey" to a random value. It has been observed that only parts of the generated value are actually random. The overall key is therefore unique and -as of today- considered sufficiently secure. However, the effective key length is not the intended one.

  • TYPO3-20051114-4

    In the past, a "Shift Reload" from the browser (AKA a GET request with the "no-cache" pragma set) cleared the TYPO3 cache of the requested page. This may be considered a potential target for Denial of Service attacks.

  • TYPO3-20051114-3

    Various security issues have been reported for PhpMyAdmin (see www.securityfocus.com/bid/15196 for details.)

  • TYPO3-20051114-2

    A Cross Site Scripting issue has been found in showpic.php.

  • TYPO3-20051114-1

    The file editor functionality in the TYPO3 Install Tool (menu option "Edit files in typo3conf/") has an option that reads "Make backup copy". If set, this will create a backup copy and append a "~" to the original file name. This leads to file names that may be delivered as text files by a web server. Thus, sensitive information (e.g. the content of localconf.php) may be disclosed.

  • TYPO3-20051107-2

    A weakness in the form validation of th_mailformplus has been discovered that may be abused to inject additional recipients in mail forms.

  • TYPO3-20051107-1

    A bug has been discovered in the "CHC Forum" (chc_forum) extension where some Javascript expressions are not properly caught when entered in forms. Thus, specially crafted entries may be used to inject malicious code.

  • TYPO3-20051010-1

    A bug has been discovered in the "Front End News Submitter" (fe_news) where SQL injection is not safely prevented and thus malicious SQL commands are potentially possible. Since the RTE enabled version (fe_rtenews) is derived from fe_news, it is affected as well.

  • TYPO3-20050822-1

    A bug has been discovered in MOC filemanager (v. 0.7.1 and earlier): An offender may gain illegal read access to files on the server.

  • TYPO3-20050812-1

    Remote exploitation of an input validation vulnerability in AWStats allows remote attackers to execute arbitrary commands. Successful exploitation results in the execution of arbitrary commands with permissions of the web service. This may compromise systems using extensions providing AWStats.

  • TYPO3-20050725-1

    A debug script exposes system information provided by phpinfo(). By default, the script can be executed by a remote user.

  • TYPO3-20050307-1

    Unless the default encryption key settings have been changed by the administrator, the TYPO3 mailform can be compromised to send mail to a wrong receipient. Thus, spam mails may be sent from a remote site.

  • TYPO3-20050304-1

    An issue has been reported where a bug in the "cmw_linklist" extension allows SQL injection attacks. In specific situations, a remote offender can cause malicious database operations.