Author: [No title]
- Showcase & Success
Usability survey
-
[No title]
The HCI-Team asks all TYPO3 users to fill out the official TYPO3 Usability Survey which is available on <LINK http://survey.typo3.org></LINK> for the next four weeks.
Read more- The Project
Succesful second TYPO3 Association General Assembly
-
[No title]
On March 10 the second General Assembly of the TYPO3 Association (T3A) took place in Rüschlikon, Switzerland.
- Product Updates & Roadmap
- Security
TYPO3-20070221-1: Email header injection
-
[No title]
A problem has been discovered where the internal form engine can be used for sending arbitrary mail headers, using it for purposes which it is not meant for.
- Security
TYPO3-20070919-1: Multiple vulnerabilities in extension mm_forum
-
[No title]
It has been discovered that the extension mm_forum is vulnerable to multiple SQL Injection attacks and multiple XSS flaws alongside other vulnerabilities.
- Security
TYPO3-20070124-1: Tip-a-friend - Header Injection
-
[No title]
A header injection problem has been found in the extension tipafriend
- Security
TYPO3-20061220-1: Remote Command Execution
-
[No title]
A critical problem has been discovered in plugin class.tx_rtehtmlarea_pi1.php that is used for spell-checking in the rtehtmlarea extension.
thumbs.php
-
[No title]
A problem has been discovered with thumbs.php providing access to unwanted files
- Security
TYPO3-20061010-1: Cross-Site Scripting in fe_adminLib.inc
-
[No title]
A problem has been discovered with fe_adminLib.inc bein vulnerable for Cross-Site Scripting (XSS)
- Security
TYPO3-20060902-1: tip-a-friend
-
[No title]
A problem has been discovered with tip-a-friend being vulnerable to Cross-Site-Scripting (XSS)
- Security
TYPO3-20060512-1: TYPO3 Security Bulletin
-
[No title]
Two problems (path traversal and SQL injection) have been discovered in the extension dam_downloads