Author: Marcus Krause
- Security
TYPO3-SA-2010-002: Multiple vulnerabilities in extension T3BLOG (t3blog)
-
Marcus Krause
It has been discovered that the extension T3BLOG (t3blog) is vulnerable to SQL Injection and Cross–Site Scripting.
Read more- Security
TYPO3-SA-2010-003: Multiple vulnerabilities in third party extensions
-
Marcus Krause
Several vulnerabilities have been found in the following third party TYPO3 extensions: Event Manager (eventmanagement), Game Article DB (game_articledb), Simple career (ml_career), Surprise Calendar (ml_surprisecalendar), Search Api Ajax Google (searchajaxgoogle), Download Manager (spr_downloadmanager)
- Product Updates & Roadmap
- Security
TYPO3-SA-2010-001: Vulnerability in TYPO3 Core
-
Marcus Krause
It has been discovered that TYPO3 Core is vulnerable to authentication bypass.
- Security
TYPO3-SA-2009-019: Blind SQL Injection vulnerability in extension Calendar Base (cal)
-
Marcus Krause
It has been discovered that the extension Calendar Base (cal) is vulnerable to Blind SQL Injection.
- Security
TYPO3-SA-2009-018: Cross-Site Scripting vulnerability in extension Direct Mail (direct_mail)
-
Marcus Krause
It has been discovered that the extension Direct Mail (direct_mail) is vulnerable to XSS.
- Security
TYPO3-SA-2009-017: Multiple vulnerabilities in third party extensions
-
Marcus Krause
Several vulnerabilities have been found in the following third party TYPO3 extensions: [AN] Search it! (an_searchit), Simple download-system with counter and categories (kk_downloader), Automatic Base Tags for RealUrl (lt_basetag), Trips (mchtrips), simple Glossar (simple_glossar), TW Productfinder (tw_productfinder), DB Integration (wfqbe)
- Security
TYPO3-SA-2009-013: Multiple vulnerabilities in third party extensions
-
Marcus Krause
Several vulnerabilities have been found in the following third party TYPO3 extensions: "AIRware Lexicon" (air_lexicon), "AST ZipCodeSearch" (ast_addresszipsearch), "Car" (car), "Event Registration" (event_registr), "Solidbase Bannermanagement" (SBbanner), "t3m_affiliate" (t3m_affiliate), "AJAX Chat" (vjchat)
- Security
TYPO3-SA-2009-012: Blind SQL Injection vulnerability in extension T3M E-Mail Marketing Tool (t3m)
-
Marcus Krause
It has been discovered that the extension T3M E-Mail Marketing Tool (t3m) is vulnerable to Blind SQL Injection attacks.
- Security
TYPO3-SA-2009-011: Cross-Site Scripting vulnerability in extension Commerce (commerce)
-
Marcus Krause
It has been discovered that the extension Commerce (commerce) is vulnerable to Cross-Site Scripting attacks.
- Security
TYPO3-SA-2009-010: Multiple vulnerabilities in third party extensions
-
Marcus Krause
Several vulnerabilities have been found in the following third party TYPO3 extensions: "CoolURI" (cooluri), "Reset backend password" (cwt_resetbepassword), "datamints Newsticker" (datamints_newsticker), "[Gobernalia] Front End News Submitter" (gb_fenewssubmit), "Mailform" (mailform), "Myth download" (myth_download), "Tour Extension" (pm_tour), "Twitter Search" (twittersearch), "Webesse E-Card" (ws_ecard) and "Webesse Image Gallery" (ws_gallery)