Author: Ekkehard Gümbel
- Developer & Technology
- Security
SECURITY-BULLETINS-CHC-FORUM-TH-MAILFORMPLUS: Security Bulletins: chc_forum, th_mailformplus
-
Ekkehard Gümbel
Two security bulletins regarding the 3rd party extensions "CHC Forum" and "th_mailformplus" have been issued today. Fixed versions are available.
Read more- Security
TYPO3-20051107-2: th_mailformplus
-
Ekkehard Gümbel
A weakness in the form validation of th_mailformplus has been discovered that may be abused to inject additional recipients in mail forms.
- Security
TYPO3-20051107-1: chc_forum
-
Ekkehard Gümbel
A bug has been discovered in the "CHC Forum" (chc_forum) extension where some Javascript expressions are not properly caught when entered in forms. Thus, specially crafted entries may be used to inject malicious code.
- Developer & Technology
- Security
SECURITY-BULLETIN-TYPO3-20051010-1-FE-NEWS: Security Bulletin TYPO3-20051010-1: fe_news
-
Ekkehard Gümbel
A bug has been discovered in the "Front End News Submitter" (fe_news) where SQL injection is not safely prevented. fe_rtenews is affected as well.
- Product Updates & Roadmap
- Security
TYPO3-20050725-1: TYPO3 Security Bulletin
-
Ekkehard Gümbel
A debug script exposes system information provided by phpinfo(). By default, the script can be executed by a remote user.
- Product Updates & Roadmap
- Security
TYPO3-20050307-1: TYPO3 Security Bulletin
-
Ekkehard Gümbel
Unless the default encryption key settings have been changed by the administrator, the TYPO3 mailform can be compromised to send mail to a wrong receipient. Thus, spam mails may be sent from a remote site.
- Security
TYPO3-20050304-1: TYPO3 Security Bulletin
-
Ekkehard Gümbel
An issue has been reported where a bug in the "cmw_linklist" extension allows SQL injection attacks. In specific situations, a remote offender can cause malicious database operations.