<?xml version="1.0" encoding="iso-8859-1"?>
<?xml-stylesheet type="text/xsl" href="http://news.typo3.org/fileadmin/news.typo3.org/rss.xsl" media="screen"?>
<rss version="0.91">
	<channel>
		
		<title>TYPO3 news: Security Team</title>
		<link>http://news.typo3.org/</link>
		<description>news.typo3.org: The TYPO3 news resource</description>
		<language>en</language>
		<image>
			<title>TYPO3 news: Security Team</title>
			<url>http://news.typo3.org/fileadmin/news.typo3.org/xmlicon.gif</url>
			<link>http://news.typo3.org/</link>
			<width>88</width>
			<height>31</height>
			<description>news.typo3.org: The TYPO3 news resource</description>
		</image>
		<docs>http://backend.userland.com/rss091</docs>
		
		
		
		<lastBuildDate>Mon, 05 May 2008 12:22:00 +0200</lastBuildDate>
		
		
		<item>
			<title>Security Bulletin TYPO3-20080505-2: Cross Site Scripting vulnerability in extension powermail</title>
			<link>http://news.typo3.org/news/article/security-bulletin-typo3-20080505-2-cross-site-scripting-vulnerability-in-extension-powermail/</link>
			<description>It has been discovered that the extension powermail is susceptible to Cross Site Scripting (XSS) attacks.</description>
		</item>
		
		<item>
			<title>Security Bulletin TYPO3-20080505-1: Multiple vulnerabilities in extension MailformPlus (th_mailformplus)</title>
			<link>http://news.typo3.org/news/article/security-bulletin-typo3-20080505-1-multiple-vulnerabilities-in-extension-mailformplus-th-mailformp/</link>
			<description>It has been discovered that the extension MailformPlus (th_mailformplus) is susceptible to Cross Site Scripting (XSS) attacks and allows Remote Code Execution.</description>
		</item>
		
		<item>
			<title>Security Bulletin TYPO3-20080416-2: SQL Injections in extensions pmk_rssnewsexport and cm_rdfexport</title>
			<link>http://news.typo3.org/news/article/security-bulletin-typo3-20080416-2-sql-injections-in-extensions-pmk-rssnewsexport-and-cm-rdfexport/</link>
			<description>It has been discovered that the extensions pmk_rssnewsexport and cm_rdfexport are vulnerable to SQL Injection attacks.</description>
		</item>
		
		<item>
			<title>Security Bulletin TYPO3-20080416-1: Multiple vulnerabilities in extension de_phpot</title>
			<link>http://news.typo3.org/news/article/security-bulletin-typo3-20080416-1-multiple-vulnerabilities-in-extension-de-phpot/</link>
			<description>It has been discovered that the extension de_phpot is vulnerable to multiple SQL Injection flaws and other types of security issues.</description>
		</item>
		
		<item>
			<title>TYPO3 Security Bulletin 20071210-1: SQL Injection in system extension indexed_search</title>
			<link>http://news.typo3.org/news/article/typo3-security-bulletin-20071210-1-sql-injection-in-system-extension-indexed-search/</link>
			<description>It has been discovered that the system extension indexed_search is vulnerable to a SQL Injection flaw.</description>
		</item>
		
		<item>
			<title>TYPO3 Security Bulletin 20070919-1: Multiple vulnerabilities in extension mm_forum</title>
			<link>http://news.typo3.org/news/article/typo3-security-bulletin-20070919-1-multiple-vulnerabilities-in-extension-mm-forum/</link>
			<description>It has been discovered that the extension mm_forum is vulnerable to multiple SQL Injection attacks and multiple XSS flaws alongside other vulnerabilities.</description>
		</item>
		
		<item>
			<title>TYPO3 Security Bulletin 20070801-1: Multiple vulnerabilities in extension ve_guestbook</title>
			<link>http://news.typo3.org/news/article/typo3-security-bulletin-20070801-1-multiple-vulnerabilities-in-extension-ve-guestbook/</link>
			<description>It has been discovered that the extension ve_guestbook is vulnerable to SQL Injection attacks. Also, a Cross Site Scripting issue has been detected.</description>
		</item>
		
		<item>
			<title>TYPO3 Security Bulletin 20070719-1: Remote shell command execution in extensions embedding PHPMailer</title>
			<link>http://news.typo3.org/news/article/typo3-security-bulletin-20070717-1-remote-shell-command-execution-in-extensions-embedding-phpmailer/</link>
			<description>Multiple TYPO3 extensions is affected by the third party tool PHPMailer, which is vulnerable to a remote shell command execution.</description>
		</item>
		
		<item>
			<title>TYPO3 Security Bulletin TYPO3-20070716-2: Information Disclosure from Extension phpmyadmin</title>
			<link>http://news.typo3.org/news/article/typo3-security-bulletin-typo3-20070716-2-information-disclosure-from-extension-phpmyadmin/</link>
			<description>An information disclosure issue has been found in the phpmyadmin extension of TYPO3 that may give access to phpinfo() information in special cases. The standalone version of phpmyadmin is not...</description>
		</item>
		
		<item>
			<title>TYPO3 Security Bulletin 20070716-1: Cross Site Scripting vulnerability in faq</title>
			<link>http://news.typo3.org/news/article/typo3-security-bulletin-20070716-1-cross-site-scripting-vulnerability-in-faq/</link>
			<description>It has been discovered that the extension faq is susceptible to cross site scripting (XSS) attacks, making it possible to execute arbitrary JavaScript.</description>
		</item>
		
	</channel>
</rss>