Skip to main navigation Skip to main content Skip to page footer

Security Advisories

All Advisories

Multiple vulnerabilities in civserv

Multiple vulnerabilities has been found in the extension civserv: Incorrect handling of input from GET/POST-variables, and allowing an attacker to…

Incorrect authentication

It has been discovered that the extension ftpbrowser is doing incorrect authentication in some files, making it open for exploiting.

Information disclosure in w4x_backup

It has been discovered that the extension w4x_backup has several security related issues, which may disclosure confidential information.

Email header injection

A problem has been discovered where the internal form engine can be used for sending arbitrary mail headers, using it for purposes which it is not…

Remote Command Execution

A critical problem has been discovered in plugin class.tx_rtehtmlarea_pi1.php that is used for spell-checking in the rtehtmlarea extension.