Dear users of TYPO3,
Security vulnerabilities have been discovered in the following third
party TYPO3 extensions:
"phpMyAdmin" (phpmyadmin),
"DR Wiki - Typo3 Wiki extension" (dr_wiki),
"WEC Discussion Forum" (wec_discussion),
"Vox populi" (mv_vox_populi),
"SB Universal Plugin" (SBuniplug),
"Simple File Browser" (simplefilebrowser),
"TU-Clausthal ODIN" (tuc_odin),
"TU-Clausthal Staff" (tuc_staff),
"WEBERkommunal Facilities" (wes_facilities)
For further information, please read the following bulletins:
TYPO3 Security Bulletin TYPO3-20081222-1: SQL injection vulnerability in
extension "phpMyAdmin" (phpmyadmin):
<http: typo3.org teams security security-bulletins typo3-20081222-1></http:>
TYPO3 Security Bulletin TYPO3-20081222-2: Multiple vulnerabilities in
extension "WEC Discussion Forum" (wec_discussion):
<http: typo3.org teams security security-bulletins typo3-20081222-2></http:>
TYPO3 Security Bulletin TYPO3-20081222-3: Cross-Site Scripting
vulnerability in extension "DR Wiki - Typo3 Wiki extension" (dr_wiki):
<http: typo3.org teams security security-bulletins typo3-20081222-3></http:>
TYPO3 Collective Security Bulletin TYPO3-20081222-4: Several
vulnerabilities in third party extension:
<http: typo3.org teams security security-bulletins typo3-20081222-4></http:>
In general the TYPO3 Security Team recommends to read the following pages:
The TYPO3 Security Cookbook:
<http: typo3.org fileadmin security-team typo3_security_cookbook_v-0.5.pdf>
Make sure you are subscribed to the TYPO3 Announce List:
<http: lists.netfielders.de cgi-bin mailman listinfo typo3-announce>
You can find all TYPO3 security bulletins at:
<http: typo3.org teams security security-bulletins></http:>
Regards,
Henning Pingel
henning@typo3.org</http:></http:>