<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>Official TYPO3 news</title>
        <description>Posts by date: 2005 / 11</description>
        <language>en</language>
        <link>https://news.typo3.com/article/archive/2005/november/blog.archive.xml</link>
        <lastBuildDate>Tue, 28 Jul 2026 15:14:39 +0200</lastBuildDate>
        
    
    
        
<item><title>TYPO3 SWOT Analysis</title><link>https://news.typo3.com/article/typo3-swot-analysis</link><comments>https://news.typo3.com/article/typo3-swot-analysis#comments</comments><pubDate>Tue, 29 Nov 2005 20:17:00 +0100</pubDate><dc:creator>News team</dc:creator><guid>https://news.typo3.com/article/typo3-swot-analysis</guid><description>The TYPO3 SWOT Analysis is designed to identify the strengths, weaknesses, opportunities, and threats (SWOT) to TYPO3. The results can help to improve and further distribute TYPO3.</description></item>


    
        
<item><title>HTMLArea 1.0.0</title><link>https://news.typo3.com/article/htmlarea-100</link><comments>https://news.typo3.com/article/htmlarea-100#comments</comments><pubDate>Tue, 29 Nov 2005 20:11:00 +0100</pubDate><dc:creator>News team</dc:creator><guid>https://news.typo3.com/article/htmlarea-100</guid><description></description></item>


    
        
<item><title>T3N Magazine 02/2005</title><link>https://news.typo3.com/article/t3n-magazine-02-2005</link><comments>https://news.typo3.com/article/t3n-magazine-02-2005#comments</comments><pubDate>Wed, 23 Nov 2005 07:32:00 +0100</pubDate><dc:creator>News team</dc:creator><guid>https://news.typo3.com/article/t3n-magazine-02-2005</guid><description>The latest issue of the German-language T3N Magazine (02/2005) can now be ordered. The reader can expect a wide spectrum of interesting articles about TYPO3 and other open source technologies.</description></item>


    
        
<item><title>Announcing the News Team</title><link>https://news.typo3.com/article/announcing-the-news-team</link><comments>https://news.typo3.com/article/announcing-the-news-team#comments</comments><pubDate>Fri, 18 Nov 2005 19:38:00 +0100</pubDate><dc:creator>Thomas Hempel</dc:creator><guid>https://news.typo3.com/article/announcing-the-news-team</guid><description></description></item>


    
        
<item><title>TYPO3 3.8.1 released</title><link>https://news.typo3.com/article/typo3-381-released</link><comments>https://news.typo3.com/article/typo3-381-released#comments</comments><pubDate>Mon, 14 Nov 2005 10:18:00 +0100</pubDate><dc:creator>Michael Stucki</dc:creator><guid>https://news.typo3.com/article/typo3-381-released</guid><description></description></item>


    
        
<item><title>SECURITY-BULLETINS-IMPORTANT-SECURITY-ENHANCEMENTS-IN-TYPO3-381: Security Bulletins: Important Security Enhancements in TYPO3 3.8.1</title><link>https://news.typo3.com/security/advisory/security-bulletins-important-security-enhancements-in-typo3-381</link><comments>https://news.typo3.com/security/advisory/security-bulletins-important-security-enhancements-in-typo3-381#comments</comments><pubDate>Mon, 14 Nov 2005 10:17:00 +0100</pubDate><dc:creator>Ekkehard Gümbel</dc:creator><guid>https://news.typo3.com/security/advisory/security-bulletins-important-security-enhancements-in-typo3-381</guid><description>Multiple TYPO3 Security Bulletins have been issued, all of which are addressed by the release of TYPO3 3.8.1.</description></item>


    
        
<item><title>TYPO3-20051114-7: TYPO3 Security Bulletin</title><link>https://news.typo3.com/security/advisory/typo3-20051114-7</link><comments>https://news.typo3.com/security/advisory/typo3-20051114-7#comments</comments><pubDate>Mon, 14 Nov 2005 10:00:00 +0100</pubDate><dc:creator>Ekkehard Gümbel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-20051114-7</guid><description>Situations are imaginable where sensitive information gets stored in the fileadmin/_temp_/ directory. If misconfigured in your web server, this directory can be browsable and therefore expose that information.</description></item>


    
        
<item><title>TYPO3-20051114-6: TYPO3 Security Bulletin</title><link>https://news.typo3.com/security/advisory/typo3-20051114-6</link><comments>https://news.typo3.com/security/advisory/typo3-20051114-6#comments</comments><pubDate>Mon, 14 Nov 2005 10:00:00 +0100</pubDate><dc:creator>Ekkehard Gümbel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-20051114-6</guid><description> Under special circumstances, setting config.baseURL (see typo3.org/documentation/document-library/doc_core_tsref/quot_CONFIG_quot/ ) to a numeric value (&quot;1&quot;) could be used to spoof a malicious baseURL into your TYPO3 cache. It has now been decided to technically prevent this misconfiguration.</description></item>


    
        
<item><title>TYPO3-20051114-5: TYPO3 Security Bulletin</title><link>https://news.typo3.com/security/advisory/typo3-20051114-5</link><comments>https://news.typo3.com/security/advisory/typo3-20051114-5#comments</comments><pubDate>Mon, 14 Nov 2005 10:00:00 +0100</pubDate><dc:creator>Ekkehard Gümbel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-20051114-5</guid><description>For convenience, the TYPO3 Install Tool provides a button sets the &quot;encryptionKey&quot; to a random value. It has been observed that only parts of the generated value are actually random. The overall key is therefore unique and -as of today- considered sufficiently secure. However, the effective key length is not the intended one.</description></item>


    
        
<item><title>TYPO3-20051114-4: TYPO3 Security Bulletin</title><link>https://news.typo3.com/security/advisory/typo3-20051114-4</link><comments>https://news.typo3.com/security/advisory/typo3-20051114-4#comments</comments><pubDate>Mon, 14 Nov 2005 10:00:00 +0100</pubDate><dc:creator>Ekkehard Gümbel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-20051114-4</guid><description>In the past, a &quot;Shift Reload&quot; from the browser (AKA a GET request with the &quot;no-cache&quot; pragma set) cleared the TYPO3 cache of the requested page. This may be considered a potential target for Denial of Service attacks.</description></item>


    
        
<item><title>TYPO3-20051114-3: TYPO3 Security Bulletin</title><link>https://news.typo3.com/security/advisory/typo3-20051114-3</link><comments>https://news.typo3.com/security/advisory/typo3-20051114-3#comments</comments><pubDate>Mon, 14 Nov 2005 10:00:00 +0100</pubDate><dc:creator>Ekkehard Gümbel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-20051114-3</guid><description>Various security issues have been reported for PhpMyAdmin (see www.securityfocus.com/bid/15196 for details.)</description></item>


    
        
<item><title>TYPO3-20051114-2: TYPO3 Security Bulletin</title><link>https://news.typo3.com/security/advisory/typo3-20051114-2</link><comments>https://news.typo3.com/security/advisory/typo3-20051114-2#comments</comments><pubDate>Mon, 14 Nov 2005 10:00:00 +0100</pubDate><dc:creator>Ekkehard Gümbel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-20051114-2</guid><description>A Cross Site Scripting issue has been found in showpic.php.</description></item>


    
        
<item><title>TYPO3-20051114-1: TYPO3 Security Bulletin</title><link>https://news.typo3.com/security/advisory/typo3-20051114-1</link><comments>https://news.typo3.com/security/advisory/typo3-20051114-1#comments</comments><pubDate>Mon, 14 Nov 2005 10:00:00 +0100</pubDate><dc:creator>Ekkehard Gümbel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-20051114-1</guid><description>The file editor functionality in the TYPO3 Install Tool (menu option &quot;Edit files in typo3conf/&quot;) has an option that reads &quot;Make backup copy&quot;. If set, this will create a backup copy and append a &quot;~&quot; to the original file name. This leads to file names that may be delivered as text files by a web server. Thus, sensitive information (e.g. the content of localconf.php) may be disclosed.</description></item>


    
        
<item><title>New Logo and Guidelines now Online</title><link>https://news.typo3.com/article/new-logo-and-guidelines-now-online</link><comments>https://news.typo3.com/article/new-logo-and-guidelines-now-online#comments</comments><pubDate>Wed, 09 Nov 2005 16:30:00 +0100</pubDate><dc:creator>Rasmus Skjoldan</dc:creator><guid>https://news.typo3.com/article/new-logo-and-guidelines-now-online</guid><description>Get prepared for the new CI to be launched on 29th. of January 2006.</description></item>


    
        
<item><title>SECURITY-BULLETINS-CHC-FORUM-TH-MAILFORMPLUS: Security Bulletins: chc_forum, th_mailformplus</title><link>https://news.typo3.com/security/advisory/security-bulletins-chc-forum-th-mailformplus</link><comments>https://news.typo3.com/security/advisory/security-bulletins-chc-forum-th-mailformplus#comments</comments><pubDate>Mon, 07 Nov 2005 15:36:18 +0100</pubDate><dc:creator>Ekkehard Gümbel</dc:creator><guid>https://news.typo3.com/security/advisory/security-bulletins-chc-forum-th-mailformplus</guid><description>Two security bulletins regarding the 3rd party extensions &quot;CHC Forum&quot; and &quot;th_mailformplus&quot; have been issued today. Fixed versions are available.</description></item>


    
        
<item><title>TYPO3-20051107-2: th_mailformplus</title><link>https://news.typo3.com/security/advisory/typo3-20051107-2</link><comments>https://news.typo3.com/security/advisory/typo3-20051107-2#comments</comments><pubDate>Mon, 07 Nov 2005 10:00:00 +0100</pubDate><dc:creator>Ekkehard Gümbel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-20051107-2</guid><description>A weakness in the form validation of th_mailformplus has been discovered that may be abused to inject additional recipients in mail forms.</description></item>


    
        
<item><title>TYPO3-20051107-1: chc_forum</title><link>https://news.typo3.com/security/advisory/typo3-20051107-1</link><comments>https://news.typo3.com/security/advisory/typo3-20051107-1#comments</comments><pubDate>Mon, 07 Nov 2005 10:00:00 +0100</pubDate><dc:creator>Ekkehard Gümbel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-20051107-1</guid><description>A bug has been discovered in the &quot;CHC Forum&quot; (chc_forum) extension where some Javascript expressions are not properly caught when entered in forms. Thus, specially crafted entries may be used to inject malicious code.</description></item>


    



    </channel>
</rss>
