Login / Status
developer.Resource
Home . Teams . Security . Security Bulletins . TYPO3-20070712-1
Sponsors
hosted by punkt.deTYPO3 and Open Source MagazineAOE Media

TYPO3 Security Bulletin TYPO3-20070712-1: Multiple vulnerabilities in extension civserv

Component Type: Third party extension. This extension is not part of the TYPO3 default installation

Affected Versions: Version 4.2.4 and all versions below

Vulnerability Type: XSS and SQL Injection

Severity: HIGH

Problem Description: Multiple vulnerabilities has been found. Incorrect handling of input from GET/POST-variables, and allowing an attacker to execute XSS and/or SQL Injection attacks.

Solution: An updated version is available from the TYPO3 extension manager at
http://typo3.org/extensions/repository/view/civserv/4.2.5/

General advice: Follow the recommendations that are given in the TYPO3 Security Cookbook.

Credits: Credits go to the company Citeq who sponsored the review of the extension and fixed the found issues. The review was performed by Peter Niederlag, Sven Gähle and partly Rupert German.