CROSS-SITE-SCRIPTING-VULNERABILITIES-IN-TYPO3-CORE: Cross Site Scripting vulnerabilities in TYPO3 core
It has been discovered that TYPO3 core is susceptible to two Cross Site Scripting (XSS) issues. The frontend plugin of system extension "felogin" and the backend module "file" are vulnerable.
Read moreTYPO3 4.3 Alpha 1
The TYPO3 Core Team is proud to announce the first alpha release of TYPO3 version 4.3. Get a short overview of the most important changes.
SECURITY-ISSUES-IN-TYPO3-EXTENSION-PHPMYADMIN-AND-SEVERAL-OTHER-THIRD-PARTY-EXTENSIONS: Security issues in TYPO3 extension phpMyAdmin and several other third party extensions
Security issues have been discovered in the following third party TYPO3 extensions: "phpMyAdmin" (phpmyadmin), "advCalendar" (advcalendar), "CMS Poll system" (cms_poll), "eLuna Page Comments" (eluna_pagecomments), "Wir ber uns" [sic] (fsmi_people), "Dictionary" (rtgdictionary).
A Common Roadmap for TYPO3
After T3CON08 21 developers, most of them member of the TYPO3 core team, met for one week to discuss possible strategies for a smooth migration from version 4 to 5. The outcome is a new joint roadmap, visionary new features for both branches and a unified core team with a common vision for future versions of TYPO3.
FLOW3 slides online
Slides from most of the talks and presentations about FLOW3 are now online.
SECURITY-ISSUES-IN-TYPO3-EXTENSION-COMMERCE-AND-SEVERAL-OTHER-THIRD-PARTY-EXTENSIONS: Security issues in TYPO3 extension Commerce and several other third party extensions
Security issues have been discovered in the following third party TYPO3 extensions: Commerce (commerce), JobControl (dmmjobcontrol), Econda Plugin (econda), Frontend Users View (feusersview), Mannschaftsliste (kiddog_playerlist), M1 Intern (m1_intern), Simple survey (simplesurvey), Page Improvements (sm_pageimprovements)
TWO-THIRD-PARTY-TYPO3-EXTENSIONS-FOUND-INSECURE: Two third party TYPO3 extensions found insecure
The extensions phpMyAdmin (phpmyadmin) and freeCap CAPTCHA (sr_freecap) have been found insecure.
TYPO3 at the Hackontest in Switzerland
TYPO3 at the Hackontest on September 24th-25th 2008
SECURITY-BULLETIN-TYPO3-20080919-1-MULTIPLE-THIRD-PARTY-EXTENSIONS-FOUND-INSECURE: Security Bulletin TYPO3-20080919-1: Multiple third party extensions found insecure
A total of 11 third party extensions have been found insecure. Please follow the links in this news item, in order to see which extensions have has been found insecure.
SECURITY-BULLETIN-TYPO3-20080916-1-CODE-EXECUTION-VULNERABILITY-IN-EXTENSION-PHPMYADMIN-1: Security Bulletin TYPO3-20080916-1: Code execution vulnerability in extension phpMyAdmin
It has been discovered that the extension phpMyAdmin (phpmyadmin) is open for code execution.