[TYPO3-announce] Security issues in several third party TYPO3 extensions

Henning Pingel henning at typo3.org
Mon Dec 22 14:22:01 CET 2008


Dear users of TYPO3,

Security vulnerabilities have been discovered in the following third
party TYPO3 extensions:

"phpMyAdmin" (phpmyadmin),
"DR Wiki - Typo3 Wiki extension" (dr_wiki),
"WEC Discussion Forum" (wec_discussion),
"Vox populi" (mv_vox_populi),
"SB Universal Plugin" (SBuniplug),
"Simple File Browser" (simplefilebrowser),
"TU-Clausthal ODIN" (tuc_odin),
"TU-Clausthal Staff" (tuc_staff),
"WEBERkommunal Facilities" (wes_facilities)

For further information, please read the following bulletins:

TYPO3 Security Bulletin TYPO3-20081222-1: SQL injection vulnerability in
extension "phpMyAdmin" (phpmyadmin):
<http://typo3.org/teams/security/security-bulletins/typo3-20081222-1/>

TYPO3 Security Bulletin TYPO3-20081222-2: Multiple vulnerabilities in
extension "WEC Discussion Forum" (wec_discussion):
<http://typo3.org/teams/security/security-bulletins/typo3-20081222-2/>

TYPO3 Security Bulletin TYPO3-20081222-3: Cross-Site Scripting
vulnerability in extension "DR Wiki - Typo3 Wiki extension" (dr_wiki):
<http://typo3.org/teams/security/security-bulletins/typo3-20081222-3/>

TYPO3 Collective Security Bulletin TYPO3-20081222-4: Several
vulnerabilities in third party extension:
<http://typo3.org/teams/security/security-bulletins/typo3-20081222-4/>

In general the TYPO3 Security Team recommends to read the following pages:

The TYPO3 Security Cookbook:
<http://typo3.org/fileadmin/security-team/typo3_security_cookbook_v-0.5.pdf>

Make sure you are subscribed to the TYPO3 Announce List:
<http://lists.netfielders.de/cgi-bin/mailman/listinfo/typo3-announce>

You can find all TYPO3 security bulletins at:
<http://typo3.org/teams/security/security-bulletins/>

Regards,

Henning Pingel
henning at typo3.org



More information about the TYPO3-announce mailing list