Skip to main navigation Skip to main content Skip to page footer

Security Advisories

All Advisories

chc_forum

A bug has been discovered in the "CHC Forum" (chc_forum) extension where some Javascript expressions are not properly caught when entered in forms.…

TYPO3 Security Bulletin

A bug has been discovered in the "Front End News Submitter" (fe_news) where SQL injection is not safely prevented and thus malicious SQL commands are…

TYPO3 Security Bulletin

A bug has been discovered in MOC filemanager (v. 0.7.1 and earlier): An offender may gain illegal read access to files on the server.

Security Bulletin TYPO3-20050822-1

A bug has been discovered in MOC filemanager (v. 0.7.1 and earlier): An offender may gain illegal read access to files on the server.

Security Bulletin TYPO3-20050812-1

Possible remote exploit with AWStats. The TYPO3 Security Team has issued a security bulletin which explains and fixes a possible problem with…

TYPO3 Security Bulletin

Remote exploitation of an input validation vulnerability in AWStats allows remote attackers to execute arbitrary commands. Successful exploitation…

Security Bulletin TYPO3-20050725-1

Possible Information leak. The TYPO3 Security Team has issued another security bulletin which explains and fixes a possible problem with a debug…

TYPO3 Security Bulletin

A debug script exposes system information provided by phpinfo(). By default, the script can be executed by a remote user.

TYPO3 Security Bulletin

Unless the default encryption key settings have been changed by the administrator, the TYPO3 mailform can be compromised to send mail to a wrong…

TYPO3 Security Bulletin

An issue has been reported where a bug in the "cmw_linklist" extension allows SQL injection attacks. In specific situations, a remote offender can…