Skip to main navigation Skip to main content Skip to page footer

Security issues in TYPO3 extension phpMyAdmin and several other third party extensions

10 November 2008 ยท Henning Pingel
Dear users of TYPO3,

It has been discovered that the extension "phpMyAdmin" (phpmyadmin) is
vulnerable to Cross-Site Scripting.

Security issues have also been discovered in the following third
party TYPO3 extensions:

"advCalendar" (advcalendar),
"CMS Poll system" (cms_poll),
"eLuna Page Comments" (eluna_pagecomments),
"Wir ber uns" [sic] (fsmi_people),
"Dictionary" (rtgdictionary).

For further information, please read the following bulletins:

TYPO3 Security Bulletin TYPO3-20081110-1: Cross-Site Scripting
vulnerability in extension phpMyAdmin (phpmyadmin)

<http: typo3.org teams security security-bulletins typo3-20081110-1></http:>

TYPO3 Collective Security Bulletin TYPO3-20081110-2: Several
vulnerabilities in third party extensions

<http: typo3.org teams security security-bulletins typo3-20081110-2></http:>

In general the TYPO3 Security Team recommends to read the following pages:

The TYPO3 Security Cookbook:
<http: typo3.org fileadmin security-team typo3_security_cookbook_v-0.5.pdf>

Make sure you are subscribed to the TYPO3 Announce List:
<http: lists.netfielders.de cgi-bin mailman listinfo typo3-announce>

You can find all TYPO3 security bulletins at:
<http: typo3.org teams security security-bulletins></http:>

Regards,

Henning Pingel
henning@typo3.org</http:></http:>