<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>Official TYPO3 news</title>
        <description>Posts by author Ekkehard Gümbel</description>
        <language>en</language>
        <link>https://news.typo3.com/article/author/ekkehard-g%C3%BCmbel/blog.author.xml</link>
        <lastBuildDate>Sat, 25 Jul 2026 03:57:46 +0200</lastBuildDate>
        
    
    
        
<item><title>TYPO3-20070716-2: Information Disclosure from phpmyadmin</title><link>https://news.typo3.com/security/advisory/typo3-20070716-2</link><comments>https://news.typo3.com/security/advisory/typo3-20070716-2#comments</comments><pubDate>Mon, 16 Jul 2007 10:00:00 +0200</pubDate><dc:creator>Ekkehard Gümbel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-20070716-2</guid><description>An information disclosure issue has been found in the phpmyadmin extension of TYPO3 that may give access to phpinfo() information in special cases. The standalone version of phpmyadmin is not affected.</description></item>


    
        
<item><title>TYPO3-SECURITY-BULLETIN-TYPO3-20070608-1-SQL-INJECTION-IN-MACINA-BANNERS-RIC-ROTATION: TYPO3 Security Bulletin TYPO3-20070608-1: SQL injection in macina_banners / ric_rotation</title><link>https://news.typo3.com/security/advisory/typo3-security-bulletin-typo3-20070608-1-sql-injection-in-macina-banners-ric-rotation</link><comments>https://news.typo3.com/security/advisory/typo3-security-bulletin-typo3-20070608-1-sql-injection-in-macina-banners-ric-rotation#comments</comments><pubDate>Mon, 11 Jun 2007 14:15:00 +0200</pubDate><dc:creator>Ekkehard Gümbel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-security-bulletin-typo3-20070608-1-sql-injection-in-macina-banners-ric-rotation</guid><description>It has been discovered that the extensions macina_banners and its descendant ric_rotation are exposed to an SQL injection issue because they fail to properly sanitize user-supplied input.</description></item>


    
        
<item><title>SECURITY-BULLETINS-IMPORTANT-SECURITY-ENHANCEMENTS-IN-TYPO3-381: Security Bulletins: Important Security Enhancements in TYPO3 3.8.1</title><link>https://news.typo3.com/security/advisory/security-bulletins-important-security-enhancements-in-typo3-381</link><comments>https://news.typo3.com/security/advisory/security-bulletins-important-security-enhancements-in-typo3-381#comments</comments><pubDate>Mon, 14 Nov 2005 10:17:00 +0100</pubDate><dc:creator>Ekkehard Gümbel</dc:creator><guid>https://news.typo3.com/security/advisory/security-bulletins-important-security-enhancements-in-typo3-381</guid><description>Multiple TYPO3 Security Bulletins have been issued, all of which are addressed by the release of TYPO3 3.8.1.</description></item>


    
        
<item><title>TYPO3-20051114-7: TYPO3 Security Bulletin</title><link>https://news.typo3.com/security/advisory/typo3-20051114-7</link><comments>https://news.typo3.com/security/advisory/typo3-20051114-7#comments</comments><pubDate>Mon, 14 Nov 2005 10:00:00 +0100</pubDate><dc:creator>Ekkehard Gümbel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-20051114-7</guid><description>Situations are imaginable where sensitive information gets stored in the fileadmin/_temp_/ directory. If misconfigured in your web server, this directory can be browsable and therefore expose that information.</description></item>


    
        
<item><title>TYPO3-20051114-3: TYPO3 Security Bulletin</title><link>https://news.typo3.com/security/advisory/typo3-20051114-3</link><comments>https://news.typo3.com/security/advisory/typo3-20051114-3#comments</comments><pubDate>Mon, 14 Nov 2005 10:00:00 +0100</pubDate><dc:creator>Ekkehard Gümbel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-20051114-3</guid><description>Various security issues have been reported for PhpMyAdmin (see www.securityfocus.com/bid/15196 for details.)</description></item>


    
        
<item><title>TYPO3-20051114-2: TYPO3 Security Bulletin</title><link>https://news.typo3.com/security/advisory/typo3-20051114-2</link><comments>https://news.typo3.com/security/advisory/typo3-20051114-2#comments</comments><pubDate>Mon, 14 Nov 2005 10:00:00 +0100</pubDate><dc:creator>Ekkehard Gümbel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-20051114-2</guid><description>A Cross Site Scripting issue has been found in showpic.php.</description></item>


    
        
<item><title>TYPO3-20051114-6: TYPO3 Security Bulletin</title><link>https://news.typo3.com/security/advisory/typo3-20051114-6</link><comments>https://news.typo3.com/security/advisory/typo3-20051114-6#comments</comments><pubDate>Mon, 14 Nov 2005 10:00:00 +0100</pubDate><dc:creator>Ekkehard Gümbel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-20051114-6</guid><description> Under special circumstances, setting config.baseURL (see typo3.org/documentation/document-library/doc_core_tsref/quot_CONFIG_quot/ ) to a numeric value (&quot;1&quot;) could be used to spoof a malicious baseURL into your TYPO3 cache. It has now been decided to technically prevent this misconfiguration.</description></item>


    
        
<item><title>TYPO3-20051114-5: TYPO3 Security Bulletin</title><link>https://news.typo3.com/security/advisory/typo3-20051114-5</link><comments>https://news.typo3.com/security/advisory/typo3-20051114-5#comments</comments><pubDate>Mon, 14 Nov 2005 10:00:00 +0100</pubDate><dc:creator>Ekkehard Gümbel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-20051114-5</guid><description>For convenience, the TYPO3 Install Tool provides a button sets the &quot;encryptionKey&quot; to a random value. It has been observed that only parts of the generated value are actually random. The overall key is therefore unique and -as of today- considered sufficiently secure. However, the effective key length is not the intended one.</description></item>


    
        
<item><title>TYPO3-20051114-4: TYPO3 Security Bulletin</title><link>https://news.typo3.com/security/advisory/typo3-20051114-4</link><comments>https://news.typo3.com/security/advisory/typo3-20051114-4#comments</comments><pubDate>Mon, 14 Nov 2005 10:00:00 +0100</pubDate><dc:creator>Ekkehard Gümbel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-20051114-4</guid><description>In the past, a &quot;Shift Reload&quot; from the browser (AKA a GET request with the &quot;no-cache&quot; pragma set) cleared the TYPO3 cache of the requested page. This may be considered a potential target for Denial of Service attacks.</description></item>


    
        
<item><title>TYPO3-20051114-1: TYPO3 Security Bulletin</title><link>https://news.typo3.com/security/advisory/typo3-20051114-1</link><comments>https://news.typo3.com/security/advisory/typo3-20051114-1#comments</comments><pubDate>Mon, 14 Nov 2005 10:00:00 +0100</pubDate><dc:creator>Ekkehard Gümbel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-20051114-1</guid><description>The file editor functionality in the TYPO3 Install Tool (menu option &quot;Edit files in typo3conf/&quot;) has an option that reads &quot;Make backup copy&quot;. If set, this will create a backup copy and append a &quot;~&quot; to the original file name. This leads to file names that may be delivered as text files by a web server. Thus, sensitive information (e.g. the content of localconf.php) may be disclosed.</description></item>


    
        
<item><title>SECURITY-BULLETINS-CHC-FORUM-TH-MAILFORMPLUS: Security Bulletins: chc_forum, th_mailformplus</title><link>https://news.typo3.com/security/advisory/security-bulletins-chc-forum-th-mailformplus</link><comments>https://news.typo3.com/security/advisory/security-bulletins-chc-forum-th-mailformplus#comments</comments><pubDate>Mon, 07 Nov 2005 15:36:18 +0100</pubDate><dc:creator>Ekkehard Gümbel</dc:creator><guid>https://news.typo3.com/security/advisory/security-bulletins-chc-forum-th-mailformplus</guid><description>Two security bulletins regarding the 3rd party extensions &quot;CHC Forum&quot; and &quot;th_mailformplus&quot; have been issued today. Fixed versions are available.</description></item>


    
        
<item><title>TYPO3-20051107-2: th_mailformplus</title><link>https://news.typo3.com/security/advisory/typo3-20051107-2</link><comments>https://news.typo3.com/security/advisory/typo3-20051107-2#comments</comments><pubDate>Mon, 07 Nov 2005 10:00:00 +0100</pubDate><dc:creator>Ekkehard Gümbel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-20051107-2</guid><description>A weakness in the form validation of th_mailformplus has been discovered that may be abused to inject additional recipients in mail forms.</description></item>


    
        
<item><title>TYPO3-20051107-1: chc_forum</title><link>https://news.typo3.com/security/advisory/typo3-20051107-1</link><comments>https://news.typo3.com/security/advisory/typo3-20051107-1#comments</comments><pubDate>Mon, 07 Nov 2005 10:00:00 +0100</pubDate><dc:creator>Ekkehard Gümbel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-20051107-1</guid><description>A bug has been discovered in the &quot;CHC Forum&quot; (chc_forum) extension where some Javascript expressions are not properly caught when entered in forms. Thus, specially crafted entries may be used to inject malicious code.</description></item>


    
        
<item><title>SECURITY-BULLETIN-TYPO3-20051010-1-FE-NEWS: Security Bulletin TYPO3-20051010-1: fe_news</title><link>https://news.typo3.com/security/advisory/security-bulletin-typo3-20051010-1-fe-news</link><comments>https://news.typo3.com/security/advisory/security-bulletin-typo3-20051010-1-fe-news#comments</comments><pubDate>Mon, 10 Oct 2005 16:24:00 +0200</pubDate><dc:creator>Ekkehard Gümbel</dc:creator><guid>https://news.typo3.com/security/advisory/security-bulletin-typo3-20051010-1-fe-news</guid><description>A bug has been discovered in the &quot;Front End News Submitter&quot; (fe_news) where SQL injection is not safely prevented. fe_rtenews is affected as well. </description></item>


    
        
<item><title>TYPO3-20050725-1: TYPO3 Security Bulletin</title><link>https://news.typo3.com/security/advisory/typo3-20050725-1</link><comments>https://news.typo3.com/security/advisory/typo3-20050725-1#comments</comments><pubDate>Mon, 25 Jul 2005 10:00:00 +0200</pubDate><dc:creator>Ekkehard Gümbel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-20050725-1</guid><description>A debug script exposes system information provided by phpinfo(). By default, the script can be executed by a remote user.</description></item>


    
        
<item><title>TYPO3-20050307-1: TYPO3 Security Bulletin</title><link>https://news.typo3.com/security/advisory/typo3-20050307-1</link><comments>https://news.typo3.com/security/advisory/typo3-20050307-1#comments</comments><pubDate>Mon, 07 Mar 2005 10:00:00 +0100</pubDate><dc:creator>Ekkehard Gümbel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-20050307-1</guid><description>Unless the default encryption key settings have been changed by the administrator, the TYPO3 mailform can be compromised to send mail to a wrong receipient. Thus, spam mails may be sent from a remote site.</description></item>


    
        
<item><title>TYPO3-20050304-1: TYPO3 Security Bulletin</title><link>https://news.typo3.com/security/advisory/typo3-20050304-1</link><comments>https://news.typo3.com/security/advisory/typo3-20050304-1#comments</comments><pubDate>Fri, 04 Mar 2005 10:00:00 +0100</pubDate><dc:creator>Ekkehard Gümbel</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-20050304-1</guid><description>An issue has been reported where a bug in the &quot;cmw_linklist&quot;
extension allows SQL injection attacks. In specific situations, a
remote offender can cause malicious database operations.</description></item>


    



    </channel>
</rss>
