• Support
    • Finding Help
    • Professional Services
    • Mailing Lists
    • IRC Chat
    • Security Bulletins
      • TYPO3 Flow
      • TYPO3 Core
      • TYPO3 Extensions

Platinum sponsors

AOE media
dkd Internet Service
Mittwald
FTI Touristik
Flagbit GmbH & Co. KG
typovision GmbH
pluswerk GmbH
netzrezepte Technologies Pvt. Ltd.
 
  • typo3.org
  • Support
  • Multiple vulnerabilities in TYPO3 Core

TYPO3-20070608-1: SQL injection in macina_banners / ric_rotation

Authors: , Category: TYPO3 Extension June 08, 2007

It has been discovered that the extensions macina_banners and its descendant ric_rotation are exposed to an SQL injection issue because they fail to properly sanitize user-supplied input.

Details

TYPO3-20070221-1: Email header injection

Authors: , Category: TYPO3 Core February 21, 2007

A problem has been discovered where the internal form engine can be used for sending arbitrary mail headers, using it for purposes which it is not meant for.

Details

TYPO3-20070919-1: Multiple vulnerabilities in extension mm_forum

Authors: , Category: TYPO3 Extension January 29, 2007

It has been discovered that the extension mm_forum is vulnerable to multiple SQL Injection attacks and multiple XSS flaws alongside other vulnerabilities.

Details

TYPO3-20070124-1: Tip-a-friend - Header Injection

Authors: , Category: TYPO3 Extension January 24, 2007

A header injection problem has been found in the extension tipafriend

Details

TYPO3-20061220-1: Remote Command Execution

Authors: , Category: TYPO3 Extension December 20, 2006

A critical problem has been discovered in plugin class.tx_rtehtmlarea_pi1.php that is used for spell-checking in the rtehtmlarea extension.

Details

TYPO3-20061205-1: thumbs.php

Authors: , Category: TYPO3 Extension December 05, 2006

A problem has been discovered with thumbs.php providing access to unwanted files

Details

TYPO3-20061010-1: Cross-Site Scripting in fe_adminLib.inc

Authors: , Category: TYPO3 Extension October 10, 2006

A problem has been discovered with fe_adminLib.inc bein vulnerable for Cross-Site Scripting (XSS)

Details

TYPO3-20060911-1: Cross-Site Scripting vulnerability in Indexed Search

Authors: Michael Stucki, Category: TYPO3 Core September 11, 2006

A problem has been discovered with indexed search being vulnerable to Cross-Site-Scripting (XSS)

Details

TYPO3-20060902-1: tip-a-friend

Authors: , Category: TYPO3 Extension September 02, 2006

A problem has been discovered with tip-a-friend being vulnerable to Cross-Site-Scripting (XSS)

Details

TYPO3-20060512-1: TYPO3 Security Bulletin

Authors: , Category: TYPO3 Extension May 12, 2006

Two problems (path traversal and SQL injection) have been discovered in the extension dam_downloads

Details
  • <<First
  • <Previous
  • …
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • Next>
  • Last>>
TYPO3
  • Go to: typo3.org
    • Buzz (TYPO3 Blogs)
    • Certification
    • TYPO3 Flow
    • Forge (Dev Platform)
    • Mailing lists
    • TYPO3 Association
    • TYPO3 Wiki
  • Loading
     
  • Home
  • About

    About

    • TYPO3 - The CMS
    • Licenses
    • TYPO3 Association
    • The Backend
    • Case Studies
    • Features

    Roadmap

    • Berlin Manifesto

    News

    • Association
    • Community
    • Development
    • Documentation
    • Security Bulletins

    The Brand

    • The TYPO3 Family
    • Brand Book
    • Style Guide

    The Trademarks

  • Community

    Community

    • Code of Conduct
    • Leadership Code of Conduct
    • Community Manager Corner
    • TYPO3 User Groups
    • Technology Supporters
    • Wallpapers
    • Merchandise

    Videos

    Events

    • Official Events
    • Community Events
    • Code Sprints
    • Archive
    • Add new Event
  • Contribute

    Contribute

    • Association Membership
    • Donate
    • Participate
    • Teams

    Projects

    • typo3.org
    • BLE
    • Google Summer of Code
  • Extensions

    Extension Repository

    • FAQ
    • What are extensions?
    • Translators
  • Support

    Support

    • Finding Help
    • Professional Services
    • Mailing Lists
    • IRC Chat
    • Security Bulletins
  • Documentation

    Documentation

    • Document Library
    • Tutorial videos
    • Wiki
    • Articles
    • Snippets
    • API
  • Download

    Release Notes

    • TYPO3 6.1 Release Notes
    • TYPO3 6.0 Release Notes
    • TYPO3 4.7 Release Notes
    • TYPO3 4.6 Release Notes
    • TYPO3 4.5 Release Notes
    • TYPO3 4.4 Release Notes
    • TYPO3 4.3 Release Notes
    • Past Changelogs

    Getting Started

    Core Documentation

    TypoScript Reference

  • Demo

© 2005-2013 TYPO3 Association. All rights reserved.

  • Contact
  • Donate
  • TYPO3 Association
  • Downloads
  • Videos
  • Flow
  • News
  • Press
  • Events
  • Sitemap
  • Legal Info
  • Licenses

Hosting Sponsors: