news.Resource
Sponsors
hosted by punkt.de
sourceforge.net
sunsite.dk

Monday 16. of July 2007 TYPO3 Security Bulletin TYPO3-20070716-2: Information Disclosure from Extension phpmyadmin

An information disclosure issue has been found in the phpmyadmin extension of TYPO3 that may give access to phpinfo() information in special cases. The standalone version of phpmyadmin is not affected.

Category: Security, www.typo3.org

By: Lars Houmark


Monday 16. of July 2007 TYPO3 Security Bulletin 20070716-1: Cross Site Scripting vulnerability in faq

It has been discovered that the extension faq is susceptible to cross site scripting (XSS) attacks, making it possible to execute arbitrary JavaScript.

Category: Security, www.typo3.org

By: Lars Houmark


Thursday 12. of July 2007 TYPO3 Security Bulletin TYPO3-20070712-1: Multiple vulnerabilities in civserv

Multiple vulnerabilities has been found. Incorrect handling of input from GET/POST-variables, and allowing an attacker to execute XSS and/or SQL Injection attacks.

Category: Security, www.typo3.org

By: Lars Houmark


Tuesday 10. of July 2007 TYPO3 Security Bulletin TYPO3-20070710-1: SQL Injection in fechangepassword

It has been discovered that the extension fechangepassword is open for a SQL injection when updating the password.

Category: Security, www.typo3.org

By: Lars Houmark


Monday 09. of July 2007 TYPO3 Security Bulletin TYPO3-20070709-1: Incorrect authentication in ftpbrowser

It has been discovered that the extension ftpbrowser is doing incorrect authentication in some files, making it open for exploiting.

Category: Security, www.typo3.org

By: Lars Houmark


Tuesday 03. of July 2007 TYPO3 Security Bulletin TYPO3-20070703-1: Multiple vulnerabilities in all variants of MySQLDumper

Multiple vulnerabilities have been found in the third party extension "mysqldumper". Full read/write access to the connected database and other related issues.

Category: Security, www.typo3.org

By: Lars Houmark


Tuesday 12. of June 2007 TYPO3 Security Bulletin TYPO3-20070612-1: Information disclosure in w4x_backup

It has been discovered that the extension w4x_backup has several security related issues, which may disclosure confidential information.

Category: Security, www.typo3.org

By: Lars Houmark


Displaying results 15 to 21 out of 36