[Typo3] SQL Injection

Karsten Dambekalns karsten at typo3.org
Fri Mar 4 13:14:22 CET 2005


Hi.

Peter Russ wrote:
> This just happened: a few weeks ago a guy asking where to post (Kaspar
> send me... ). And now this:
> 
> [quote]
> Two week ago I found a SQL Inejetion vulnerabilitie in Typo3 (in the
> links-section/module/whatever you call it).
> I didn't really try to develope an exploit because I thought typo3 would
> directly react.

Ok, stop.

Until Kapser confirms that this got lost in his mailbox, no accusations,
please. Until now we only have the claim that someone was informed two
weeks ago, but nothing more.

As has been said, information about how to handle such things will be more
visible shortly.

Karsten
-- 
Karsten Dambekalns
TYPO3 Association - Active Member
http://association.typo3.org/



More information about the TYPO3-english mailing list