Skip to main navigation Skip to main content Skip to page footer

Security issues in several third party TYPO3 extensions

22 December 2008 ยท Henning Pingel
Dear users of TYPO3,

Security vulnerabilities have been discovered in the following third
party TYPO3 extensions:

"phpMyAdmin" (phpmyadmin),
"DR Wiki - Typo3 Wiki extension" (dr_wiki),
"WEC Discussion Forum" (wec_discussion),
"Vox populi" (mv_vox_populi),
"SB Universal Plugin" (SBuniplug),
"Simple File Browser" (simplefilebrowser),
"TU-Clausthal ODIN" (tuc_odin),
"TU-Clausthal Staff" (tuc_staff),
"WEBERkommunal Facilities" (wes_facilities)

For further information, please read the following bulletins:

TYPO3 Security Bulletin TYPO3-20081222-1: SQL injection vulnerability in
extension "phpMyAdmin" (phpmyadmin):
<http: typo3.org teams security security-bulletins typo3-20081222-1></http:>

TYPO3 Security Bulletin TYPO3-20081222-2: Multiple vulnerabilities in
extension "WEC Discussion Forum" (wec_discussion):
<http: typo3.org teams security security-bulletins typo3-20081222-2></http:>

TYPO3 Security Bulletin TYPO3-20081222-3: Cross-Site Scripting
vulnerability in extension "DR Wiki - Typo3 Wiki extension" (dr_wiki):
<http: typo3.org teams security security-bulletins typo3-20081222-3></http:>

TYPO3 Collective Security Bulletin TYPO3-20081222-4: Several
vulnerabilities in third party extension:
<http: typo3.org teams security security-bulletins typo3-20081222-4></http:>

In general the TYPO3 Security Team recommends to read the following pages:

The TYPO3 Security Cookbook:
<http: typo3.org fileadmin security-team typo3_security_cookbook_v-0.5.pdf>

Make sure you are subscribed to the TYPO3 Announce List:
<http: lists.netfielders.de cgi-bin mailman listinfo typo3-announce>

You can find all TYPO3 security bulletins at:
<http: typo3.org teams security security-bulletins></http:>

Regards,

Henning Pingel
henning@typo3.org</http:></http:>