TYPO3-20070919-1: Multiple vulnerabilities in extension mm_forum
It has been discovered that the extension mm_forum is vulnerable to multiple SQL Injection attacks and multiple XSS flaws alongside other vulnerabilities.
Read moreTYPO3-20070124-1: Tip-a-friend - Header Injection
A header injection problem has been found in the extension tipafriend
TYPO3-20061220-1: Remote Command Execution
A critical problem has been discovered in plugin class.tx_rtehtmlarea_pi1.php that is used for spell-checking in the rtehtmlarea extension.
thumbs.php
A problem has been discovered with thumbs.php providing access to unwanted files
TYPO3-20061010-1: Cross-Site Scripting in fe_adminLib.inc
A problem has been discovered with fe_adminLib.inc bein vulnerable for Cross-Site Scripting (XSS)
TYPO3-20060902-1: tip-a-friend
A problem has been discovered with tip-a-friend being vulnerable to Cross-Site-Scripting (XSS)
TYPO3-20060512-1: TYPO3 Security Bulletin
Two problems (path traversal and SQL injection) have been discovered in the extension dam_downloads
TYPO3-20060501-1: TYPO3 Security Bulletin
A weakness in the display of forum messages of chc_forum has been discovered that may be used to execute arbitrary SQL