Security issues in several third party TYPO3 extensions including "Frontend User Registration" (sr_feuser_register), "404 Error Page Handling" (error_404_handling) and "Tip-A-Friend" (tipafriend)

Categories: Security Created by Helmut Hummel
Security vulnerabilities have been discovered in the third party TYPO3 extensions including sr_feuser_register, error_404_handling and tipafriend

For further information on the issue in the extension "Frontend User Registration" (sr_feuser_register), please read the related advisory TYPO3-SA-2010-009 that was published today:

http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-009/

For further information on the issue in the extension "404 Error Page Handling" (error_404_handling), please read the related advisory TYPO3-SA-2010-011 that was published today:

http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-011/

For further information on the issue in the extension "Tip-A-Friend" (tipafriend), please read the related advisory TYPO3-SA-2010-010 that was published today:

http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-010/

  

In general the TYPO3 Security Team recommends to read the following pages:

The TYPO3 Security Cookbook:
http://typo3.org/fileadmin/security-team/typo3_security_cookbook_v-0.5.pdf

Make sure you are subscribed to the TYPO3 Announce List:
http://lists.typo3.org/cgi-bin/mailman/listinfo/typo3-announce

See all TYPO3 security advisories:
https://typo3.org/security/advisory/