Skip to main navigation Skip to main content Skip to page footer

Multiple vulnerabilities found in TYPO3 Core

16 December 2010 ยท TYPO3 Security Team
Dear users of TYPO3!

It has been discovered that TYPO3 Core is vulnerable to Arbitrary Code Execution, Path Traversal, Cross-Site Scripting (XSS), SQL Injection and Information Disclosure.


Please read the advisory for a description and solutions on these issues:

<http: typo3.org teams security security-bulletins typo3-sa-2010-022></http:>



In general the TYPO3 Security Team recommends to read the following pages:

The TYPO3 Security Cookbook:
<http: typo3.org fileadmin security-team typo3_security_cookbook_v-0.5.pdf>

Make sure you are subscribed to the TYPO3 Announce List:
<http: lists.typo3.org cgi-bin mailman listinfo typo3-announce>

See all TYPO3 security advisories:
<http: typo3.org teams security security-bulletins></http:>


Kind Regards,

Helmut Hummel
Member of the TYPO3 Security Team

--
TYPO3 Security Team homepage: <a href="http://typo3.org/teams/security/" target="_blank" rel="noreferrer">http://typo3.org/teams/security/</a>

E-Mail: security@typo3.org
_______________________________________________
TYPO3-announce mailing list
TYPO3-announce at lists.typo3.org
<a href="http://lists.typo3.org/cgi-bin/mailman/listinfo/typo3-announce" target="_blank" rel="noreferrer">http://lists.typo3.org/cgi-bin/mailman/listinfo/typo3-announce</a></http:></http:>