[TYPO3-announce] Security issues in several third party TYPO3 extensions

Henning Pingel henning at typo3.org
Mon Dec 22 14:22:01 CET 2008

Dear users of TYPO3,

Security vulnerabilities have been discovered in the following third
party TYPO3 extensions:

"phpMyAdmin" (phpmyadmin),
"DR Wiki - Typo3 Wiki extension" (dr_wiki),
"WEC Discussion Forum" (wec_discussion),
"Vox populi" (mv_vox_populi),
"SB Universal Plugin" (SBuniplug),
"Simple File Browser" (simplefilebrowser),
"TU-Clausthal ODIN" (tuc_odin),
"TU-Clausthal Staff" (tuc_staff),
"WEBERkommunal Facilities" (wes_facilities)

For further information, please read the following bulletins:

TYPO3 Security Bulletin TYPO3-20081222-1: SQL injection vulnerability in
extension "phpMyAdmin" (phpmyadmin):

TYPO3 Security Bulletin TYPO3-20081222-2: Multiple vulnerabilities in
extension "WEC Discussion Forum" (wec_discussion):

TYPO3 Security Bulletin TYPO3-20081222-3: Cross-Site Scripting
vulnerability in extension "DR Wiki - Typo3 Wiki extension" (dr_wiki):

TYPO3 Collective Security Bulletin TYPO3-20081222-4: Several
vulnerabilities in third party extension:

In general the TYPO3 Security Team recommends to read the following pages:

The TYPO3 Security Cookbook:

Make sure you are subscribed to the TYPO3 Announce List:

You can find all TYPO3 security bulletins at:


Henning Pingel
henning at typo3.org

More information about the TYPO3-announce mailing list