[Ticket#2012020210000031] Security issues in several third party TYPO3 extensions
Dear TYPO3 users, Several vulnerabilities have been found in the following third party TYPO3 extensions: UrlTool (aeurltool) BE User Switch (beuserswitch) Post data records to facebook (bc_post2facebook) CSS styled Filelinks (css_filelinks) Modern FAQ (irfaq) Additional TCA Forms (jftcaforms) White Papers (mm_whtppr) Kitchen recipe (mv_cooking) Documents download (rtg_files) Euro Calculator (skt_eurocalc) System Utilities (sysutils) Terminal PHP Shell (terminal) Category-System (toi_category) Webservices for TYPO3 (typo3_webservice) Yet another Google search (ya_googlesearch) For further information on all CSB (Collective Security Bulletin) issues, please read the related advisory TYPO3-EXT-SA-2012-001 that was published today: http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2012-001/ In general the TYPO3 Security Team recommends to read the following pages: The TYPO3 Security Guide: http://typo3.org/documentation/document-library/extension-manuals/doc_guide_security/current/ Make sure you are subscribed to the TYPO3 Announce List: http://lists.typo3.org/cgi-bin/mailman/listinfo/typo3-announce See all TYPO3 security advisories for TYPO3 third party extensions: http://typo3.org/teams/security/security-bulletins/typo3-extensions/ Regards, Marcus Krause Member of the TYPO3 Security Team -- TYPO3 Security Team homepage: http://typo3.org/teams/security/ E-Mail: security@typo3.org Please note: When replying to this e-mail, please leave the header intact.