[Ticket#2013021910000016] Security issues in several third party TYPO3 extensions including cooluri and static_info_tables
Dear TYPO3 users, Several vulnerabilities have been found in the following third party TYPO3 extensions: CoolURI (cooluri) Static Info Tables (static_info_tables) Fluid Extbase Development Framework (fed) My quiz and poll (myquizpoll) RSS feed from records (push2rss_3ds) Slideshare (slideshare) WEC Discussion Forum (wec_discussion) For further information on the issue in the extension "CoolURI" (cooluri), please read the related advisory TYPO3-EXT-SA-2013-003 that was published today: http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2013-003/ For further information on the issue in the extension "Static Info Tables" (static_info_tables), please read the related advisory TYPO3-EXT-SA-2013-004 that was published today: http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2013-004/ For further information on all CSB (Collective Security Bulletin) issues, please read the related advisory TYPO3-EXT-SA-2013-005 that was published today: http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2013-005/ In general the TYPO3 Security Team recommends to read the following pages: The TYPO3 Security Guide: http://typo3.org/documentation/document-library/extension-manuals/doc_guide_security/current/ Make sure you are subscribed to the TYPO3 Announce List: http://lists.typo3.org/cgi-bin/mailman/listinfo/typo3-announce See all TYPO3 security advisories for TYPO3 third party extensions: http://typo3.org/teams/security/security-bulletins/typo3-extensions/ Regards, Franz G. Jahn Member of the TYPO3 Security Team -- TYPO3 Security Team homepage: http://typo3.org/teams/security/ E-Mail: security@typo3.org Please note: When replying to this e-mail, please leave the header intact.