Multiple security issues found in TYPO3 core

Categories: Security Created by Helmut Hummel

It has been discovered that improper error handling could lead to cache flooding in TYPO3 Core and that the prepared statement database API potentially allows SQL Injections.

Please read the advisories for a description and solutions of all the above mentioned issues:

TYPO3 Security Bulletin TYPO3-CORE-SA-2011-002: Potential SQL injection vulnerabilitiy in TYPO3 Core

TYPO3 Security Bulletin TYPO3-CORE-SA-2011-003: Improper error handling could lead to cache flooding in TYPO3 Core

In general the TYPO3 Security Team recommends to read the following pages: