[Ticket#2013092510000064] Security issues in several third party TYPO3 ectensions
Dear TYPO3 users, Several vulnerabilities have been found in the following third party TYPO3 extensions: Direct Mail (direct_mail) RealURL: speaking paths for TYPO3 (realurl) Formhandler (formhandler) AWStats (cc_awstats) booking (booking) ICS AWStats (ics_awstats) Simple Image Gallery (iflowgallery) Ratsinformationssystem (RIS) (cronmm_ratsinfo) Frontend User Registration (ke_userregister) AWStats with individual access (meta_beawstatsind) Powermail double opt-in (powermail_optin) smarty (smarty) Youtube Channel Videos (youtubevideos) For further information on the issue in the extension "Direct Mail" (direct_mail), please read the related advisory TYPO3-EXT-SA-2013-014 that was published today: http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa- 2013-014/ For further information on the issue in the extension "RealURL: speaking paths for TYPO3" (realurl), please read the related advisory TYPO3-EXT-SA-2013-015 that was published today: http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa- 2013-015/ For further information on the issue in the extension "Formhandler" (formhandler), please read the related advisory TYPO3-EXT-SA-2013-016 that was published today: http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa- 2013-016/ For further information on the issue in the extension "AWStats" (cc_awstats), please read the related advisory TYPO3-EXT-SA-2013-018 that was published today: http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa- 2013-018/ For further information on all CSB (Collective Security Bulletin) issues, please read the related advisory TYPO3-EXT-SA-2013-017 that was published today: http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa- 2013-017/ In general the TYPO3 Security Team recommends to read the following pages: The TYPO3 Security Guide: http://docs.typo3.org/typo3cms/SecurityGuide/ Make sure you are subscribed to the TYPO3 Announce List: http://lists.typo3.org/cgi-bin/mailman/listinfo/typo3-announce See all TYPO3 security advisories for TYPO3 third party extensions: http://typo3.org/teams/security/security-bulletins/typo3-extensions/ Regards, Georg Ringer Member of the TYPO3 Security Team -- TYPO3 Security Team homepage: http://typo3.org/teams/security/ E-Mail: security@typo3.org Please note: When replying to this e-mail, please leave the header intact.