Author: Ekkehard Gümbel
- Security
TYPO3-20070716-2: Information Disclosure from phpmyadmin
-
Ekkehard Gümbel
An information disclosure issue has been found in the phpmyadmin extension of TYPO3 that may give access to phpinfo() information in special cases. The standalone version of phpmyadmin is not affected.
Read more- Developer & Technology
- Security
TYPO3-SECURITY-BULLETIN-TYPO3-20070608-1-SQL-INJECTION-IN-MACINA-BANNERS-RIC-ROTATION: TYPO3 Security Bulletin TYPO3-20070608-1: SQL injection in macina_banners / ric_rotation
-
Ekkehard Gümbel
It has been discovered that the extensions macina_banners and its descendant ric_rotation are exposed to an SQL injection issue because they fail to properly sanitize user-supplied input.
- Developer & Technology
- Security
SECURITY-BULLETINS-IMPORTANT-SECURITY-ENHANCEMENTS-IN-TYPO3-381: Security Bulletins: Important Security Enhancements in TYPO3 3.8.1
-
Ekkehard Gümbel
Multiple TYPO3 Security Bulletins have been issued, all of which are addressed by the release of TYPO3 3.8.1.
- Product Updates & Roadmap
- Security
TYPO3-20051114-7: TYPO3 Security Bulletin
-
Ekkehard Gümbel
Situations are imaginable where sensitive information gets stored in the fileadmin/_temp_/ directory. If misconfigured in your web server, this directory can be browsable and therefore expose that information.
- Security
TYPO3-20051114-3: TYPO3 Security Bulletin
-
Ekkehard Gümbel
Various security issues have been reported for PhpMyAdmin (see www.securityfocus.com/bid/15196 for details.)
- Product Updates & Roadmap
- Security
TYPO3-20051114-2: TYPO3 Security Bulletin
-
Ekkehard Gümbel
A Cross Site Scripting issue has been found in showpic.php.
- Product Updates & Roadmap
- Security
TYPO3-20051114-6: TYPO3 Security Bulletin
-
Ekkehard Gümbel
Under special circumstances, setting config.baseURL (see typo3.org/documentation/document-library/doc_core_tsref/quot_CONFIG_quot/ ) to a numeric value ("1") could be used to spoof a malicious baseURL into your TYPO3 cache. It has now been decided to technically prevent this misconfiguration.
- Product Updates & Roadmap
- Security
TYPO3-20051114-5: TYPO3 Security Bulletin
-
Ekkehard Gümbel
For convenience, the TYPO3 Install Tool provides a button sets the "encryptionKey" to a random value. It has been observed that only parts of the generated value are actually random. The overall key is therefore unique and -as of today- considered sufficiently secure. However, the effective key length is not the intended one.
- Product Updates & Roadmap
- Security
TYPO3-20051114-4: TYPO3 Security Bulletin
-
Ekkehard Gümbel
In the past, a "Shift Reload" from the browser (AKA a GET request with the "no-cache" pragma set) cleared the TYPO3 cache of the requested page. This may be considered a potential target for Denial of Service attacks.
- Product Updates & Roadmap
- Security
TYPO3-20051114-1: TYPO3 Security Bulletin
-
Ekkehard Gümbel
The file editor functionality in the TYPO3 Install Tool (menu option "Edit files in typo3conf/") has an option that reads "Make backup copy". If set, this will create a backup copy and append a "~" to the original file name. This leads to file names that may be delivered as text files by a web server. Thus, sensitive information (e.g. the content of localconf.php) may be disclosed.