An information disclosure issue has been found in the phpmyadmin extension of TYPO3 that may give access to phpinfo() information in special cases. The standalone version of phpmyadmin is not affected.
It has been discovered that the extension faq is susceptible to cross site scripting (XSS) attacks, making it possible to execute arbitrary JavaScript.
Multiple vulnerabilities has been found. Incorrect handling of input from GET/POST-variables, and allowing an attacker to execute XSS and/or SQL Injection attacks.
It has been discovered that the extension fechangepassword is open for a SQL injection when updating the password.
It has been discovered that the extension ftpbrowser is doing incorrect authentication in some files, making it open for exploiting.
Multiple vulnerabilities have been found in the third party extension "mysqldumper". Full read/write access to the connected database and other related issues.
It has been discovered that the extension w4x_backup has several security related issues, which may disclosure confidential information.