[TYPO3] TYPO3 Security Bulletin TYPO3-20070712-1: Multiple vulnerabilities in extension civserv

Lars Houmark lars at typo3.org
Thu Jul 12 12:20:50 CEST 2007


Dear users of TYPO3,

Reviewing the extension civserv revealed that the extension was open  
for multiple vulnerabilities.

==== Component Type ====
Third party extension. This extension is not part of the TYPO3  
default installation

==== Affected Versions ====
Version 4.2.4 and all versions below

==== Vulnerability Type ====
XSS and SQL Injection

==== Severity ====
HIGH

==== Problem Description ====
Multiple vulnerabilities has been found. Incorrect handling of input  
from GET/POST-variables, and allowing an attacker to execute XSS and/ 
or SQL Injection attacks.

==== Solution ====
An updated version is available from the TYPO3 extension manager at
http://typo3.org/extensions/repository/view/civserv/4.2.5/

==== General advice ====
  Follow the recommendations that are given in the TYPO3 Security  
Cookbook [1].

==== Credits ====
Credits go to the company Citeq who sponsored the review of the  
extension and fixed the found issues. The review was performed by  
Peter Niederlag, Sven Gähle and partly Rupert German.

[1] http://typo3.org/fileadmin/security-team/ 
typo3_security_cookbook_v-0.5.pdf

Regards,

Lars Houmark
lars at typo3.org





More information about the TYPO3-english mailing list