[TYPO3-dev] TYPO3 Security Bulletin 20070221-1: Email header injection

Luc de Louw luc.delouw at bit-heads.ch
Wed Feb 21 08:33:41 CET 2007


Lars Houmark wrote:
> Dear users of TYPO3,
> 
> A problem has been discovered where the internal form engine can be used
> for sending arbitrary mail headers, using it for purposes which it is
> not meant for.
> 
> ==== Component Type ====
> TYPO3 Core
> 
> ==== Affected Versions ====
> Below 4.0.5, 4.1beta, 4.1RC1

Does that mean that Versions 3.8.x are also affected?

Thanks,

Luc




More information about the TYPO3-dev mailing list