news.Resource
Sponsors
hosted by punkt.de
sourceforge.net
sunsite.dk
10.07.07 20:06 Age: 308 days

TYPO3 Security Bulletin TYPO3-20070710-1: SQL Injection in fechangepassword

Category: Security, www.typo3.org

By: Lars Houmark

It has been discovered that the extension fechangepassword is open for a SQL injection when updating the password.

Please read the entire security bulletin here:

TYPO3 Security Bulletin TYPO3-20070710-1: SQL Injection in fechangepassword


We also recommend that you subscribe to the TYPO3 Announce List, which is a low-traffic list, where only important announces like this one is being brought.