Author: [No title]
- Showcase & Success
T3N Magazine releases six current English-TYPO3-Articles
-
[No title]
For the 9th time <LINK http://t3n.yeebase.com>T3N Magazine for Open Source and Web</LINK> updated their article database. Six stories from the current issue (No. 9) have recently been translated for your free reading pleasure.
Read more- Security
TYPO3-20070801-1: Multiple vulnerabilities in extension ve_guestbook
-
[No title]
It has been discovered that the extension ve_guestbook is vulnerable to SQL Injection attacks. Also, a Cross Site Scripting issue has been detected.
- Security
TYPO3-20070719-1: Remote shell command execution in extensions embedding PHPMailer
-
[No title]
Multiple TYPO3 extensions is affected by the third party tool PHPMailer, which is vulnerable to a remote shell command execution.
- Security
TYPO3-20070716-1: Cross Site Scripting vulnerability in faq
-
[No title]
It has been discovered that the extension faq is susceptible to cross site scripting (XSS) attacks, making it possible to execute arbitrary JavaScript.
- Security
TYPO3-20070712-1: Multiple vulnerabilities in civserv
-
[No title]
Multiple vulnerabilities has been found in the extension civserv: Incorrect handling of input from GET/POST-variables, and allowing an attacker to execute XSS and/or SQL Injection attacks.
- Security
TYPO3-20070710-1: SQL Injection in fechangepassword
-
[No title]
It has been discovered that the extension fechangepassword is open for a SQL injection when updating the password.
- Security
TYPO3-20070709-1: Incorrect authentication
-
[No title]
It has been discovered that the extension ftpbrowser is doing incorrect authentication in some files, making it open for exploiting.
- Security
TYPO3-20070703-1: Multiple vulnerabilities in all variants of MySQLDumper
-
[No title]
Multiple vulnerabilities have been found in the third party extension "mysqldumper". Full read/write access to the connected database and other related issues.
- Security
TYPO3-20070612-1: Information disclosure in w4x_backup
-
[No title]
It has been discovered that the extension w4x_backup has several security related issues, which may disclosure confidential information.
- Security
TYPO3-20070608-1: SQL injection in macina_banners / ric_rotation
-
[No title]
It has been discovered that the extensions macina_banners and its descendant ric_rotation are exposed to an SQL injection issue because they fail to properly sanitize user-supplied input.