donators

n@work Internet Informationssysteme GmbH
Your ad here

supported by

 TYPO3 Hamburg
 TYPO3 Anbieter

Advertising

Security Bulletin: civserv

By: Thomas

12.07.07 12:42 Age: 1 yrs

Hi,

another security hole was found in a third-party extension.

Dear users of TYPO3,

 

Reviewing the extension civserv revealed that the extension was open for multiple vulnerabilities.

 

==== Component Type ====

Third party extension. This extension is not part of the TYPO3 default installation

 

==== Affected Versions ====

Version 4.2.4 and all versions below

 

==== Vulnerability Type ====

XSS and SQL Injection

 

==== Severity ====

HIGH

 

==== Problem Description ====

Multiple vulnerabilities has been found. Incorrect handling of input from GET/POST-variables, and allowing an attacker to execute XSS and/or SQL Injection attacks.

 

==== Solution ====

An updated version is available from the TYPO3 extension manager at

typo3.org/extensions/repository/view/civserv/4.2.5/

 

==== General advice ====

Follow the recommendations that are given in the TYPO3 Security Cookbook [1].

 

==== Credits ====

Credits go to the company Citeq who sponsored the review of the extension and fixed the found issues. The review was performed by Peter Niederlag, Sven Gähle and partly Rupert German.

Update your installations!

 

 

Greets,

Thomas

Leave a Reply

You have to activate JavaScript to post comments!

Calendar

July 2007
M T W T F S S
« Jun   Aug »
 1
02340506708
09101112131415
16171819202122
23242526272829
3031  

Latest comments

  • Thomas

    Hi, check out http://forge.typo3.org/wiki/flow3-f3pr/php53. I think I have to check my encodin...

  • Tschüge

    Hallo Könntest du in einem (mini-)Tutorial kurz erkären wie du unter Linux die PHP-Version 5.3alpha...

  • Jens

    A Network functionality! I think, tt_clap events are mainly driven by the crowed spirit. So I wo...

  • Steffen M?ller

    Hi Thomas, When I started to work today, I felt soooo tired of hacking boring PHP code for a bori...

  • Thomas Hempel

    Hello, thanks for your comments. I did some testing concerning audio on iPhone and I can say that...

Advertising