<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>Official TYPO3 news</title>
        <description>Posts by author Lars Houmark</description>
        <language>en</language>
        <link>https://news.typo3.com/article/author/lars-houmark/blog.author.xml</link>
        <lastBuildDate>Fri, 24 Jul 2026 03:38:55 +0200</lastBuildDate>
        
    
    
        
<item><title>INFORMATION-DISCLOSURE-XSS-IN-TYPO3-CORE: Information Disclosure &amp; XSS in TYPO3 Core</title><link>https://news.typo3.com/security/advisory/information-disclosure-xss-in-typo3-core</link><comments>https://news.typo3.com/security/advisory/information-disclosure-xss-in-typo3-core#comments</comments><pubDate>Tue, 10 Feb 2009 10:00:00 +0100</pubDate><dc:creator>Lars Houmark</dc:creator><guid>https://news.typo3.com/security/advisory/information-disclosure-xss-in-typo3-core</guid><description>It has been discovered that TYPO3 Core is vulnerable to Information Disclosure and Cross-Site Scripting.</description></item>


    
        
<item><title>TYPO3-SA-2009-002: Information Disclosure &amp; XSS in TYPO3 Core</title><link>https://news.typo3.com/security/advisory/typo3-sa-2009-002</link><comments>https://news.typo3.com/security/advisory/typo3-sa-2009-002#comments</comments><pubDate>Tue, 10 Feb 2009 10:00:00 +0100</pubDate><dc:creator>Lars Houmark</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-sa-2009-002</guid><description>It has been discovered that TYPO3 Core is vulnerable to Information Disclosure and Cross-Site Scripting.</description></item>


    
        
<item><title>IMPORTANT-SECURITY-BULLETIN-PRE-ANNOUNCEMENT: Important Security-Bulletin Pre-Announcement</title><link>https://news.typo3.com/security/advisory/important-security-bulletin-pre-announcement</link><comments>https://news.typo3.com/security/advisory/important-security-bulletin-pre-announcement#comments</comments><pubDate>Mon, 09 Feb 2009 00:00:00 +0100</pubDate><dc:creator>Lars Houmark</dc:creator><guid>https://news.typo3.com/security/advisory/important-security-bulletin-pre-announcement</guid><description>Serious security issue found in TYPO3 core.</description></item>


    
        
<item><title>MULTIPLE-SECURITY-ISSUES-FOUND-IN-TYPO3-CORE: Multiple security issues found in TYPO3 core</title><link>https://news.typo3.com/security/advisory/multiple-security-issues-found-in-typo3-core</link><comments>https://news.typo3.com/security/advisory/multiple-security-issues-found-in-typo3-core#comments</comments><pubDate>Tue, 20 Jan 2009 17:23:00 +0100</pubDate><dc:creator>Lars Houmark</dc:creator><guid>https://news.typo3.com/security/advisory/multiple-security-issues-found-in-typo3-core</guid><description>It has been discovered that TYPO3 Core is vulnerable to Broken Authentication and Session Management, Cross-Site Scripting, Insecure Randomness and Remote Command Execution.</description></item>


    
        
<item><title>TWO-THIRD-PARTY-TYPO3-EXTENSIONS-FOUND-INSECURE: Two third party TYPO3 extensions found insecure</title><link>https://news.typo3.com/security/advisory/two-third-party-typo3-extensions-found-insecure</link><comments>https://news.typo3.com/security/advisory/two-third-party-typo3-extensions-found-insecure#comments</comments><pubDate>Wed, 24 Sep 2008 09:45:00 +0200</pubDate><dc:creator>Lars Houmark</dc:creator><guid>https://news.typo3.com/security/advisory/two-third-party-typo3-extensions-found-insecure</guid><description>The extensions phpMyAdmin (phpmyadmin) and freeCap CAPTCHA (sr_freecap) have been found insecure.</description></item>


    
        
<item><title>SECURITY-BULLETIN-TYPO3-20080919-1-MULTIPLE-THIRD-PARTY-EXTENSIONS-FOUND-INSECURE: Security Bulletin TYPO3-20080919-1: Multiple third party extensions found insecure</title><link>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080919-1-multiple-third-party-extensions-found-insecure</link><comments>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080919-1-multiple-third-party-extensions-found-insecure#comments</comments><pubDate>Fri, 19 Sep 2008 07:43:00 +0200</pubDate><dc:creator>Lars Houmark</dc:creator><guid>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080919-1-multiple-third-party-extensions-found-insecure</guid><description>A total of 11 third party extensions have been found insecure. Please follow the links in this news item, in order to see which extensions have has been found insecure.</description></item>


    
        
<item><title>SECURITY-BULLETIN-TYPO3-20080916-1-CODE-EXECUTION-VULNERABILITY-IN-EXTENSION-PHPMYADMIN-1: Security Bulletin TYPO3-20080916-1: Code execution vulnerability in extension phpMyAdmin</title><link>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080916-1-code-execution-vulnerability-in-extension-phpmyadmin-1</link><comments>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080916-1-code-execution-vulnerability-in-extension-phpmyadmin-1#comments</comments><pubDate>Tue, 16 Sep 2008 23:02:00 +0200</pubDate><dc:creator>Lars Houmark</dc:creator><guid>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080916-1-code-execution-vulnerability-in-extension-phpmyadmin-1</guid><description>It has been discovered that the extension phpMyAdmin (phpmyadmin) is open for code execution.</description></item>


    
        
<item><title>MULTIPLE-SECURITY-ISSUES-IN-THIRD-PARTY-TYPO3-EXTENSIONS: Multiple security issues in third party TYPO3 extensions</title><link>https://news.typo3.com/security/advisory/multiple-security-issues-in-third-party-typo3-extensions</link><comments>https://news.typo3.com/security/advisory/multiple-security-issues-in-third-party-typo3-extensions#comments</comments><pubDate>Tue, 01 Jul 2008 07:30:00 +0200</pubDate><dc:creator>Lars Houmark</dc:creator><guid>https://news.typo3.com/security/advisory/multiple-security-issues-in-third-party-typo3-extensions</guid><description>A total of 15 third party extensions has been found insecure. Please follow the links in this news item, in order to see which extensions have has been found insecure.</description></item>


    
        
<item><title>SECURITY-BULLETIN-TYPO3-20080619-1-SEVERAL-VULNERABILITIES-HAVE-BEEN-FOUND-IN-TYPO3-THIRD-PARTY-EXTENSIONS: Security Bulletin TYPO3-20080619-1: Several vulnerabilities have been found in TYPO3 third party extensions</title><link>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080619-1-several-vulnerabilities-have-been-found-in-typo3-third-party-extensions</link><comments>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080619-1-several-vulnerabilities-have-been-found-in-typo3-third-party-extensions#comments</comments><pubDate>Thu, 19 Jun 2008 06:30:00 +0200</pubDate><dc:creator>Lars Houmark</dc:creator><guid>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080619-1-several-vulnerabilities-have-been-found-in-typo3-third-party-extensions</guid><description>Several vulnerabilities have been found in TYPO3 third party extensions.</description></item>


    
        
<item><title>SECURITY-BULLETIN-TYPO3-20080611-1-MULTIPLE-VULNERABILITIES-IN-TYPO3-CORE: Security Bulletin TYPO3-20080611-1: Multiple vulnerabilities in TYPO3 Core</title><link>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080611-1-multiple-vulnerabilities-in-typo3-core</link><comments>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080611-1-multiple-vulnerabilities-in-typo3-core#comments</comments><pubDate>Wed, 11 Jun 2008 11:28:00 +0200</pubDate><dc:creator>Lars Houmark</dc:creator><guid>https://news.typo3.com/security/advisory/security-bulletin-typo3-20080611-1-multiple-vulnerabilities-in-typo3-core</guid><description>It has been discovered that the default value of the TYPO3 configuration variable fileDenyPattern allows arbitrary code execution on Apache web servers. Besides that, the library fe_adminlib.inc allows Cross Site Scripting (XSS).</description></item>


    
        
<item><title>TYPO3-SECURITY-BULLETIN-20071210-1-SQL-INJECTION-IN-SYSTEM-EXTENSION-INDEXED-SEARCH: TYPO3 Security Bulletin 20071210-1: SQL Injection in system extension indexed_search</title><link>https://news.typo3.com/security/advisory/typo3-security-bulletin-20071210-1-sql-injection-in-system-extension-indexed-search</link><comments>https://news.typo3.com/security/advisory/typo3-security-bulletin-20071210-1-sql-injection-in-system-extension-indexed-search#comments</comments><pubDate>Mon, 10 Dec 2007 11:00:00 +0100</pubDate><dc:creator>Lars Houmark</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-security-bulletin-20071210-1-sql-injection-in-system-extension-indexed-search</guid><description>It has been discovered that the system extension indexed_search is vulnerable to a SQL Injection flaw.</description></item>


    
        
<item><title>TYPO3-SECURITY-BULLETIN-20070919-1-MULTIPLE-VULNERABILITIES-IN-EXTENSION-MM-FORUM: TYPO3 Security Bulletin 20070919-1: Multiple vulnerabilities in extension mm_forum</title><link>https://news.typo3.com/security/advisory/typo3-security-bulletin-20070919-1-multiple-vulnerabilities-in-extension-mm-forum</link><comments>https://news.typo3.com/security/advisory/typo3-security-bulletin-20070919-1-multiple-vulnerabilities-in-extension-mm-forum#comments</comments><pubDate>Wed, 19 Sep 2007 14:36:00 +0200</pubDate><dc:creator>Lars Houmark</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-security-bulletin-20070919-1-multiple-vulnerabilities-in-extension-mm-forum</guid><description>It has been discovered that the extension mm_forum is vulnerable to multiple SQL Injection attacks and multiple XSS flaws alongside other vulnerabilities.</description></item>


    
        
<item><title>TYPO3-SECURITY-BULLETIN-20070801-1-MULTIPLE-VULNERABILITIES-IN-EXTENSION-VE-GUESTBOOK: TYPO3 Security Bulletin 20070801-1: Multiple vulnerabilities in extension ve_guestbook</title><link>https://news.typo3.com/security/advisory/typo3-security-bulletin-20070801-1-multiple-vulnerabilities-in-extension-ve-guestbook</link><comments>https://news.typo3.com/security/advisory/typo3-security-bulletin-20070801-1-multiple-vulnerabilities-in-extension-ve-guestbook#comments</comments><pubDate>Wed, 01 Aug 2007 19:50:00 +0200</pubDate><dc:creator>Lars Houmark</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-security-bulletin-20070801-1-multiple-vulnerabilities-in-extension-ve-guestbook</guid><description>It has been discovered that the extension ve_guestbook is vulnerable to SQL Injection attacks. Also, a Cross Site Scripting issue has been detected.</description></item>


    
        
<item><title>TYPO3-SECURITY-BULLETIN-20070719-1-REMOTE-SHELL-COMMAND-EXECUTION-IN-EXTENSIONS-EMBEDDING-PHPMAILER: TYPO3 Security Bulletin 20070719-1: Remote shell command execution in extensions embedding PHPMailer</title><link>https://news.typo3.com/security/advisory/typo3-security-bulletin-20070719-1-remote-shell-command-execution-in-extensions-embedding-phpmailer</link><comments>https://news.typo3.com/security/advisory/typo3-security-bulletin-20070719-1-remote-shell-command-execution-in-extensions-embedding-phpmailer#comments</comments><pubDate>Thu, 19 Jul 2007 16:30:00 +0200</pubDate><dc:creator>Lars Houmark</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-security-bulletin-20070719-1-remote-shell-command-execution-in-extensions-embedding-phpmailer</guid><description>Multiple TYPO3 extensions is affected by the third party tool PHPMailer, which is vulnerable to a remote shell command execution.</description></item>


    
        
<item><title>TYPO3-SECURITY-BULLETIN-TYPO3-20070716-2-INFORMATION-DISCLOSURE-FROM-EXTENSION-PHPMYADMIN: TYPO3 Security Bulletin TYPO3-20070716-2: Information Disclosure from Extension phpmyadmin</title><link>https://news.typo3.com/security/advisory/typo3-security-bulletin-typo3-20070716-2-information-disclosure-from-extension-phpmyadmin</link><comments>https://news.typo3.com/security/advisory/typo3-security-bulletin-typo3-20070716-2-information-disclosure-from-extension-phpmyadmin#comments</comments><pubDate>Mon, 16 Jul 2007 23:50:00 +0200</pubDate><dc:creator>Lars Houmark</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-security-bulletin-typo3-20070716-2-information-disclosure-from-extension-phpmyadmin</guid><description>An information disclosure issue has been found in the phpmyadmin extension of TYPO3 that may give access to phpinfo() information in special cases. The standalone version of phpmyadmin is not affected.</description></item>


    
        
<item><title>TYPO3-SECURITY-BULLETIN-20070716-1-CROSS-SITE-SCRIPTING-VULNERABILITY-IN-FAQ: TYPO3 Security Bulletin 20070716-1: Cross Site Scripting vulnerability in faq</title><link>https://news.typo3.com/security/advisory/typo3-security-bulletin-20070716-1-cross-site-scripting-vulnerability-in-faq</link><comments>https://news.typo3.com/security/advisory/typo3-security-bulletin-20070716-1-cross-site-scripting-vulnerability-in-faq#comments</comments><pubDate>Mon, 16 Jul 2007 13:17:00 +0200</pubDate><dc:creator>Lars Houmark</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-security-bulletin-20070716-1-cross-site-scripting-vulnerability-in-faq</guid><description>It has been discovered that the extension faq is susceptible to cross site scripting (XSS) attacks, making it possible to execute arbitrary JavaScript.</description></item>


    
        
<item><title>TYPO3-SECURITY-BULLETIN-TYPO3-20070712-1-MULTIPLE-VULNERABILITIES-IN-CIVSERV: TYPO3 Security Bulletin TYPO3-20070712-1: Multiple vulnerabilities in civserv</title><link>https://news.typo3.com/security/advisory/typo3-security-bulletin-typo3-20070712-1-multiple-vulnerabilities-in-civserv</link><comments>https://news.typo3.com/security/advisory/typo3-security-bulletin-typo3-20070712-1-multiple-vulnerabilities-in-civserv#comments</comments><pubDate>Thu, 12 Jul 2007 12:17:00 +0200</pubDate><dc:creator>Lars Houmark</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-security-bulletin-typo3-20070712-1-multiple-vulnerabilities-in-civserv</guid><description>Multiple vulnerabilities has been found. Incorrect handling of input from GET/POST-variables, and allowing an attacker to execute XSS and/or SQL Injection attacks.</description></item>


    
        
<item><title>TYPO3-SECURITY-BULLETIN-TYPO3-20070710-1-SQL-INJECTION-IN-FECHANGEPASSWORD: TYPO3 Security Bulletin TYPO3-20070710-1: SQL Injection in fechangepassword</title><link>https://news.typo3.com/security/advisory/typo3-security-bulletin-typo3-20070710-1-sql-injection-in-fechangepassword</link><comments>https://news.typo3.com/security/advisory/typo3-security-bulletin-typo3-20070710-1-sql-injection-in-fechangepassword#comments</comments><pubDate>Tue, 10 Jul 2007 20:06:00 +0200</pubDate><dc:creator>Lars Houmark</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-security-bulletin-typo3-20070710-1-sql-injection-in-fechangepassword</guid><description>It has been discovered that the extension fechangepassword is open for a SQL injection when updating the password.</description></item>


    
        
<item><title>TYPO3-SECURITY-BULLETIN-TYPO3-20070709-1-INCORRECT-AUTHENTICATION-IN-FTPBROWSER: TYPO3 Security Bulletin TYPO3-20070709-1: Incorrect authentication in ftpbrowser</title><link>https://news.typo3.com/security/advisory/typo3-security-bulletin-typo3-20070709-1-incorrect-authentication-in-ftpbrowser</link><comments>https://news.typo3.com/security/advisory/typo3-security-bulletin-typo3-20070709-1-incorrect-authentication-in-ftpbrowser#comments</comments><pubDate>Mon, 09 Jul 2007 14:22:00 +0200</pubDate><dc:creator>Lars Houmark</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-security-bulletin-typo3-20070709-1-incorrect-authentication-in-ftpbrowser</guid><description>It has been discovered that the extension ftpbrowser is doing incorrect authentication in some files, making it open for exploiting.</description></item>


    
        
<item><title>TYPO3-SECURITY-BULLETIN-TYPO3-20070703-1-MULTIPLE-VULNERABILITIES-IN-ALL-VARIANTS-OF-MYSQLDUMPER: TYPO3 Security Bulletin TYPO3-20070703-1: Multiple vulnerabilities in all variants of MySQLDumper</title><link>https://news.typo3.com/security/advisory/typo3-security-bulletin-typo3-20070703-1-multiple-vulnerabilities-in-all-variants-of-mysqldumper</link><comments>https://news.typo3.com/security/advisory/typo3-security-bulletin-typo3-20070703-1-multiple-vulnerabilities-in-all-variants-of-mysqldumper#comments</comments><pubDate>Tue, 03 Jul 2007 23:35:00 +0200</pubDate><dc:creator>Lars Houmark</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-security-bulletin-typo3-20070703-1-multiple-vulnerabilities-in-all-variants-of-mysqldumper</guid><description>Multiple vulnerabilities have been found in the third party extension &quot;mysqldumper&quot;. Full read/write access to the connected database and other related issues.</description></item>


    
        
<item><title>TYPO3-SECURITY-BULLETIN-TYPO3-20070612-1-INFORMATION-DISCLOSURE-IN-W4X-BACKUP: TYPO3 Security Bulletin TYPO3-20070612-1: Information disclosure in w4x_backup</title><link>https://news.typo3.com/security/advisory/typo3-security-bulletin-typo3-20070612-1-information-disclosure-in-w4x-backup</link><comments>https://news.typo3.com/security/advisory/typo3-security-bulletin-typo3-20070612-1-information-disclosure-in-w4x-backup#comments</comments><pubDate>Tue, 12 Jun 2007 13:17:00 +0200</pubDate><dc:creator>Lars Houmark</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-security-bulletin-typo3-20070612-1-information-disclosure-in-w4x-backup</guid><description>It has been discovered that the extension w4x_backup has several security related issues, which may disclosure confidential information.</description></item>


    
        
<item><title>TYPO3-SECURITY-BULLETIN-TYPO3-20070221-1-EMAIL-HEADER-INJECTION: TYPO3 Security Bulletin TYPO3-20070221-1: Email header injection</title><link>https://news.typo3.com/security/advisory/typo3-security-bulletin-typo3-20070221-1-email-header-injection</link><comments>https://news.typo3.com/security/advisory/typo3-security-bulletin-typo3-20070221-1-email-header-injection#comments</comments><pubDate>Wed, 21 Feb 2007 05:30:00 +0100</pubDate><dc:creator>Lars Houmark</dc:creator><guid>https://news.typo3.com/security/advisory/typo3-security-bulletin-typo3-20070221-1-email-header-injection</guid><description>A problem has been discovered where the internal form engine can be used for sending arbitrary mail headers, using it for purposes which it is not meant for.</description></item>


    



    </channel>
</rss>
