TYPO3-20050725-1: TYPO3 Security Bulletin
A debug script exposes system information provided by phpinfo(). By default, the script can be executed by a remote user.
Read moreTYPO3-20050307-1: TYPO3 Security Bulletin
Unless the default encryption key settings have been changed by the administrator, the TYPO3 mailform can be compromised to send mail to a wrong receipient. Thus, spam mails may be sent from a remote site.