Author: [No title]

Usability survey

The HCI-Team asks all TYPO3 users to fill out the official TYPO3 Usability Survey which is available on <LINK http://survey.typo3.org></LINK> for the next four weeks.

Read more

TYPO3-20070221-1: Email header injection

A problem has been discovered where the internal form engine can be used for sending arbitrary mail headers, using it for purposes which it is not meant for.

TYPO3-20061220-1: Remote Command Execution

A critical problem has been discovered in plugin class.tx_rtehtmlarea_pi1.php that is used for spell-checking in the rtehtmlarea extension.

thumbs.php

A problem has been discovered with thumbs.php providing access to unwanted files

TYPO3-20060902-1: tip-a-friend

A problem has been discovered with tip-a-friend being vulnerable to Cross-Site-Scripting (XSS)