SECURITY-BULLETIN-TYPO3-20080513-1-MULTIPLE-VULNERABILITIES-IN-EXTENSION-WT-GALLERY-WT-GALLERY: Security Bulletin TYPO3-20080513-1: Multiple vulnerabilities in extension WT Gallery (wt_gallery)
It has been discovered that the extension WT Gallery (wt_gallery) is susceptible to Path Traversal and Cross Site Scripting (XSS) attacks. Besides that, it may disclose sensitive information.
Read moreTYPO3 v5 project report: April 2008
For all of you who are not that deeply involved in the making of TYPO3 v5, I have collected the most important bits of last month's activities.
SECURITY-BULLETIN-TYPO3-20080505-2-CROSS-SITE-SCRIPTING-VULNERABILITY-IN-EXTENSION-POWERMAIL: Security Bulletin TYPO3-20080505-2: Cross Site Scripting vulnerability in extension powermail
It has been discovered that the extension powermail is susceptible to Cross Site Scripting (XSS) attacks.
SECURITY-BULLETIN-TYPO3-20080505-1-MULTIPLE-VULNERABILITIES-IN-EXTENSION-MAILFORMPLUS-TH-MAILFORMPLUS: Security Bulletin TYPO3-20080505-1: Multiple vulnerabilities in extension MailformPlus (th_mailformplus)
It has been discovered that the extension MailformPlus (th_mailformplus) is susceptible to Cross Site Scripting (XSS) attacks and allows Remote Code Execution.
TYPO3 Association releases Version 4.2: Focus on Usability and Performance Improvements
BAAR - The TYPO3 Association 4.x Development Team has released a new version of their very successful open source project. TYPO3 has been downloaded over 3.000.000 times from Sourceforge.org which makes it one of the World's leading enterprise Open Source products. The main focus of the new 4.2 version is improving usability, but there are also many enhancements for system administrators and developers. Including bug fixes, there are nearly 650 enhancements in TYPO3 4.2.
TYPO3 4.2 RC 2
The core team is proud to announce the second Release Candidate of TYPO3 version 4.2. We now think that we do have all blockers for a final release fixed so that if no critical bugs are found in this release candidate this will be the final release of TYPO3 4.2.
SECURITY-BULLETIN-TYPO3-20080416-2-SQL-INJECTIONS-IN-EXTENSIONS-PMK-RSSNEWSEXPORT-AND-CM-RDFEXPORT: Security Bulletin TYPO3-20080416-2: SQL Injections in extensions pmk_rssnewsexport and cm_rdfexport
It has been discovered that the extensions pmk_rssnewsexport and cm_rdfexport are vulnerable to SQL Injection attacks.
SECURITY-BULLETIN-TYPO3-20080416-1-MULTIPLE-VULNERABILITIES-IN-EXTENSION-DE-PHPOT: Security Bulletin TYPO3-20080416-1: Multiple vulnerabilities in extension de_phpot
It has been discovered that the extension de_phpot is vulnerable to multiple SQL Injection flaws and other types of security issues.
DEV3 - TYPO3 and FLOW3 Development Tools for Eclipse
Sebastian Böttger and David Brühlmeier join forces to develop a TYPO3 / FLOW3 Development Environment based on Eclipse.
TYPO3 4.2 RC 1
The core team is proud to announce the first Release Candidate of TYPO3 version 4.2. After the previous three Beta versions this Release Candidate starts the ramp down of TYPO3 4.2 development.