<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/xsl" href="http://news.typo3.org/fileadmin/news.typo3.org/rss.xsl" media="screen"?>
<rss version="0.91">
	<channel>
		
		<title>TYPO3 news: Security Team</title>
		<link>http://news.typo3.org/</link>
		<description>news.typo3.org: The TYPO3 news resource</description>
		<language>en</language>
		<image>
			<title>TYPO3 news: Security Team</title>
			<url>http://news.typo3.org/fileadmin/news.typo3.org/xmlicon.gif</url>
			<link>http://news.typo3.org/</link>
			<width>88</width>
			<height>31</height>
			<description>news.typo3.org: The TYPO3 news resource</description>
		</image>
		<docs>http://backend.userland.com/rss091</docs>
		
		
		
		<lastBuildDate>Fri, 19 Mar 2010 11:57:00 +0100</lastBuildDate>
		
		
		<item>
			<title>Security issue in third party TYPO3 extension &quot;Calendar Base&quot; (cal)</title>
			<link>http://news.typo3.org/news/article/security-issue-in-third-party-typo3-extension-calendar-base-cal/</link>
			<description>A security vulnerabilitiy has been discovered in the third party TYPO3 extension &quot;Calendar Base&quot;.</description>
		</item>
		
		<item>
			<title>Security issues found in TYPO3 core</title>
			<link>http://news.typo3.org/news/article/security-issues-found-in-typo3-core/</link>
			<description>It has been discovered that TYPO3 Core is vulnerable to Cross-Site Scripting, Authentication Bypass for frontend users and Information Disclosure.</description>
		</item>
		
		<item>
			<title>Security issues in third party TYPO3 extensions including t3blog</title>
			<link>http://news.typo3.org/news/article/security-issues-in-third-party-typo3-extension-t3blog/</link>
			<description>Security vulnerabilities have been discovered in third party TYPO3 extensions t3blog, eventmanagement, game_articledb, ml_career, ml_surprisecalendar, searchajaxgoogle and spr_downloadmanager</description>
		</item>
		
		<item>
			<title>Security issue found in TYPO3 core</title>
			<link>http://news.typo3.org/news/article/security-issue-found-in-typo3-430-core/</link>
			<description>It has been discovered that using the openid system extension in TYPO3 4.3.0 can lead to an authentication bypass under certain circumstances.</description>
		</item>
		
		<item>
			<title>Security issues in several third party TYPO3 extensions</title>
			<link>http://news.typo3.org/news/article/security-issues-in-several-third-party-typo3-extensions-1/</link>
			<description>Security vulnerabilities have been discovered in following third party TYPO3 extensions: MK-AnydropdownMenu (mk_anydropdownmenu), Photo Book (goof_fotoboek), SB Folderdownload (sb_folderdownload),...</description>
		</item>
		
		<item>
			<title>Security issues in several third party TYPO3 extensions including car, aba_watchdog, dr_blob, nl_listman, xds_staff, danp_documentdirs, ste_prayer2, pd_resources, hs_religiousartgallery, ste_parish_admin, pd_calendar</title>
			<link>http://news.typo3.org/news/article/security-issues-in-several-third-party-typo3-extensions-including-car-aba-watchdog-dr-blob-nl-lis/</link>
			<description>Security vulnerabilities have been discovered in following third party TYPO3 extensions: Car (car), TYPO3 Watchdog (aba_watchdog), File list (dr_blob), ListMan (nl_listman), XDS Staff List...</description>
		</item>
		
		<item>
			<title>Security issues in several third party TYPO3 extensions including cal, direct_mail, an_searchit, kk_downloader, lt_basetag, mchtrips, simple_glossar, tw_productfinder, wfqbe</title>
			<link>http://news.typo3.org/news/article/security-issues-in-several-third-party-typo3-extensions-including-phpmyadmin-solr-maag-randomimage/</link>
			<description>Security vulnerabilities have been discovered in following third party TYPO3 extensions: &quot;Calendar Base&quot; (cal), &quot;Direct Mail&quot; (direct_mail), &quot;[AN] Search it!&quot; (an_searchit), &quot;Simple download-system...</description>
		</item>
		
		<item>
			<title>Multiple security issues found in TYPO3 core</title>
			<link>http://news.typo3.org/news/article/multiple-security-issues-found-in-typo3-core-1/</link>
			<description>It has been discovered that the TYPO3 Core is vulnerable to Cross-site scripting, SQL-Injection, Remote shell command execution, Information Disclosure and insecure Install Tool...</description>
		</item>
		
		<item>
			<title>Security issues in several third party TYPO3 extensions including commerce and t3m</title>
			<link>http://news.typo3.org/news/article/security-issues-in-several-third-party-typo3-extensions-including-commerce-and-t3m/</link>
			<description>Several vulnerabilities have been found in the following third party TYPO3 extensions: &quot;Commerce&quot; (commerce), &quot;T3M E-Mail Marketing Tool&quot; (t3m), &quot;AIRware Lexicon&quot; (air_lexicon), &quot;AST ZipCodeSearch&quot;...</description>
		</item>
		
		<item>
			<title>Security issues in several third party TYPO3 extensions including cooluri, cwt_resetbepassword, datamints_newsticker, gb_fenewssubmit, mailform, myth_download, pm_tour, twittersearch, ws_ecard, ws_gallery</title>
			<link>http://news.typo3.org/news/article/security-issues-in-several-third-party-typo3-extensions-including-cooluri-cwt-resetbepassword-data/</link>
			<description>Several vulnerabilities have been found in the following third party TYPO3 extensions:  &quot;CoolURI&quot; (cooluri), &quot;Reset backend password&quot; (cwt_resetbepassword), &quot;datamints Newsticker&quot;...</description>
		</item>
		
	</channel>
</rss>