<?xml version="1.0" encoding="iso-8859-1"?>
<feed version="0.3" xmlns="http://purl.org/atom/ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xml:lang="en">
	
	<title>TYPO3 news: Security Team</title>
	<link rel="alternate" type="text/html" href="http://news.typo3.org/" />
	<modified>2008-05-05T12:22:00+02:00</modified>
	<generator url="http://www.typo3.com" version="4.1">TYPO3 - get.content.right</generator>
	<tagline>news.typo3.org: The TYPO3 news resource</tagline>
		
	
		
	<entry>
		<title>Security Bulletin TYPO3-20080505-2: Cross Site Scripting vulnerability in extension powermail</title>
		<link rel="alternate" type="text/html" href="http://news.typo3.org/news/article/security-bulletin-typo3-20080505-2-cross-site-scripting-vulnerability-in-extension-powermail/"/>
		<modified>2008-05-05T07:19:03+02:00</modified>
		<issued>2008-05-02T22:41:31+02:00</issued>
		<created>2008-05-05T07:18:00+02:00</created>
		<id>tag:.typo3.org,2008:article469</id>
		<author>
			<name>Henning Pingel</name>
		</author>
		<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://news.typo3.org/">
			<![CDATA[It has been discovered that the extension powermail is susceptible to Cross Site Scripting (XSS) attacks.]]>
		</content>
	</entry>
		
	<entry>
		<title>Security Bulletin TYPO3-20080505-1: Multiple vulnerabilities in extension MailformPlus (th_mailformplus)</title>
		<link rel="alternate" type="text/html" href="http://news.typo3.org/news/article/security-bulletin-typo3-20080505-1-multiple-vulnerabilities-in-extension-mailformplus-th-mailformp/"/>
		<modified>2008-05-05T07:14:22+02:00</modified>
		<issued>2008-05-02T22:12:34+02:00</issued>
		<created>2008-05-05T07:14:00+02:00</created>
		<id>tag:.typo3.org,2008:article468</id>
		<author>
			<name>Henning Pingel</name>
		</author>
		<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://news.typo3.org/">
			<![CDATA[It has been discovered that the extension MailformPlus (th_mailformplus) is susceptible to Cross Site Scripting (XSS) attacks and allows Remote Code Execution.]]>
		</content>
	</entry>
		
	<entry>
		<title>Security Bulletin TYPO3-20080416-2: SQL Injections in extensions pmk_rssnewsexport and cm_rdfexport</title>
		<link rel="alternate" type="text/html" href="http://news.typo3.org/news/article/security-bulletin-typo3-20080416-2-sql-injections-in-extensions-pmk-rssnewsexport-and-cm-rdfexport/"/>
		<modified>2008-04-16T07:11:47+02:00</modified>
		<issued>2008-04-14T21:28:30+02:00</issued>
		<created>2008-04-16T07:32:00+02:00</created>
		<id>tag:.typo3.org,2008:article458</id>
		<author>
			<name>Henning Pingel</name>
		</author>
		<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://news.typo3.org/">
			<![CDATA[It has been discovered that the extensions pmk_rssnewsexport and cm_rdfexport are vulnerable to SQL Injection attacks.]]>
		</content>
	</entry>
		
	<entry>
		<title>Security Bulletin TYPO3-20080416-1: Multiple vulnerabilities in extension de_phpot</title>
		<link rel="alternate" type="text/html" href="http://news.typo3.org/news/article/security-bulletin-typo3-20080416-1-multiple-vulnerabilities-in-extension-de-phpot/"/>
		<modified>2008-04-16T07:08:22+02:00</modified>
		<issued>2008-04-14T22:30:26+02:00</issued>
		<created>2008-04-16T07:05:00+02:00</created>
		<id>tag:.typo3.org,2008:article459</id>
		<author>
			<name>Henning Pingel</name>
		</author>
		<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://news.typo3.org/">
			<![CDATA[It has been discovered that the extension de_phpot is vulnerable to multiple SQL Injection flaws and other types of security issues.]]>
		</content>
	</entry>
		
	<entry>
		<title>TYPO3 Security Bulletin 20071210-1: SQL Injection in system extension indexed_search</title>
		<link rel="alternate" type="text/html" href="http://news.typo3.org/news/article/typo3-security-bulletin-20071210-1-sql-injection-in-system-extension-indexed-search/"/>
		<modified>2007-12-10T21:32:44+01:00</modified>
		<issued>2007-12-10T17:33:35+01:00</issued>
		<created>2007-12-10T11:00:00+01:00</created>
		<id>tag:.typo3.org,2007:article402</id>
		<author>
			<name>Lars Houmark</name>
		</author>
		<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://news.typo3.org/">
			<![CDATA[It has been discovered that the system extension indexed_search is vulnerable to a SQL Injection flaw.]]>
		</content>
	</entry>
		
	<entry>
		<title>TYPO3 Security Bulletin 20070919-1: Multiple vulnerabilities in extension mm_forum</title>
		<link rel="alternate" type="text/html" href="http://news.typo3.org/news/article/typo3-security-bulletin-20070919-1-multiple-vulnerabilities-in-extension-mm-forum/"/>
		<modified>2007-09-19T20:20:05+02:00</modified>
		<issued>2007-09-19T11:44:00+02:00</issued>
		<created>2007-09-19T14:36:00+02:00</created>
		<id>tag:.typo3.org,2007:article362</id>
		<author>
			<name>Lars Houmark</name>
		</author>
		<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://news.typo3.org/">
			<![CDATA[It has been discovered that the extension mm_forum is vulnerable to multiple SQL Injection attacks and multiple XSS flaws alongside other vulnerabilities.]]>
		</content>
	</entry>
		
	<entry>
		<title>TYPO3 Security Bulletin 20070801-1: Multiple vulnerabilities in extension ve_guestbook</title>
		<link rel="alternate" type="text/html" href="http://news.typo3.org/news/article/typo3-security-bulletin-20070801-1-multiple-vulnerabilities-in-extension-ve-guestbook/"/>
		<modified>2007-08-01T19:44:59+02:00</modified>
		<issued>2007-08-01T19:43:31+02:00</issued>
		<created>2007-08-01T19:50:00+02:00</created>
		<id>tag:.typo3.org,2007:article341</id>
		<author>
			<name>Lars Houmark</name>
		</author>
		<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://news.typo3.org/">
			<![CDATA[It has been discovered that the extension ve_guestbook is vulnerable to SQL Injection attacks. Also, a Cross Site Scripting issue has been detected.]]>
		</content>
	</entry>
		
	<entry>
		<title>TYPO3 Security Bulletin 20070719-1: Remote shell command execution in extensions embedding PHPMailer</title>
		<link rel="alternate" type="text/html" href="http://news.typo3.org/news/article/typo3-security-bulletin-20070717-1-remote-shell-command-execution-in-extensions-embedding-phpmailer/"/>
		<modified>2007-07-19T17:09:50+02:00</modified>
		<issued>2007-07-13T16:44:48+02:00</issued>
		<created>2007-07-19T16:30:00+02:00</created>
		<id>tag:.typo3.org,2007:article330</id>
		<author>
			<name>Lars Houmark</name>
		</author>
		<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://news.typo3.org/">
			<![CDATA[Multiple TYPO3 extensions is affected by the third party tool PHPMailer, which is vulnerable to a remote shell command execution.]]>
		</content>
	</entry>
		
	<entry>
		<title>TYPO3 Security Bulletin TYPO3-20070716-2: Information Disclosure from Extension phpmyadmin</title>
		<link rel="alternate" type="text/html" href="http://news.typo3.org/news/article/typo3-security-bulletin-typo3-20070716-2-information-disclosure-from-extension-phpmyadmin/"/>
		<modified>2007-07-16T23:55:24+02:00</modified>
		<issued>2007-07-16T16:53:43+02:00</issued>
		<created>2007-07-16T23:50:00+02:00</created>
		<id>tag:.typo3.org,2007:article332</id>
		<author>
			<name>Lars Houmark</name>
		</author>
		<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://news.typo3.org/">
			<![CDATA[An information disclosure issue has been found in the phpmyadmin extension of TYPO3 that may give access to phpinfo() information in special cases. The standalone version of phpmyadmin is not...]]>
		</content>
	</entry>
		
	<entry>
		<title>TYPO3 Security Bulletin 20070716-1: Cross Site Scripting vulnerability in faq</title>
		<link rel="alternate" type="text/html" href="http://news.typo3.org/news/article/typo3-security-bulletin-20070716-1-cross-site-scripting-vulnerability-in-faq/"/>
		<modified>2007-07-16T13:24:01+02:00</modified>
		<issued>2007-07-14T15:31:11+02:00</issued>
		<created>2007-07-16T13:17:00+02:00</created>
		<id>tag:.typo3.org,2007:article331</id>
		<author>
			<name>Lars Houmark</name>
		</author>
		<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://news.typo3.org/">
			<![CDATA[It has been discovered that the extension faq is susceptible to cross site scripting (XSS) attacks, making it possible to execute arbitrary JavaScript.]]>
		</content>
	</entry>
	
</feed>
