It has been discovered that the extension faq is susceptible to cross site scripting (XSS) attacks, making it possible to execute arbitrary JavaScript.
Multiple vulnerabilities has been found. Incorrect handling of input from GET/POST-variables, and allowing an attacker to execute XSS and/or SQL Injection attacks.
It has been discovered that the extension fechangepassword is open for a SQL injection when updating the password.
It has been discovered that the extension ftpbrowser is doing incorrect authentication in some files, making it open for exploiting.
Multiple vulnerabilities have been found in the third party extension "mysqldumper". Full read/write access to the connected database and other related issues.
The deadline for sending in your proposition for a talk or a tutorial at T3CON07 is closing in rapidly, but we're still open for suggestions! So if you were still doubting if your concept for a talk is interesting for the TYPO3...
The next snowboard Tour will take place from Sunday 30.th of March to Sunday 06.th of April 2008 at the Mountainhostel Crap Sogn Gion. Details about the tour and registration can be found here: