Please read this bulletin for a description and solutions on all the above mentioned issues:
typo3.org/teams/security/security-bulletins/typo3-sa-2009-002/
We also recommend that you subscribe to the TYPO3 Announce List to receive all future Security Bulletins and other important TYPO3 news.