Hi,
another security hole was found in a third-party extension.
Dear users of TYPO3,
Reviewing the extension civserv revealed that the extension was open for multiple vulnerabilities.
==== Component Type ====
Third party extension. This extension is not part of the TYPO3 default installation
==== Affected Versions ====
Version 4.2.4 and all versions below
==== Vulnerability Type ====
XSS and SQL Injection
==== Severity ====
HIGH
==== Problem Description ====
Multiple vulnerabilities has been found. Incorrect handling of input from GET/POST-variables, and allowing an attacker to execute XSS and/or SQL Injection attacks.
==== Solution ====
An updated version is available from the TYPO3 extension manager at
typo3.org/extensions/repository/view/civserv/4.2.5/
==== General advice ====
Follow the recommendations that are given in the TYPO3 Security Cookbook [1].
==== Credits ====
Credits go to the company Citeq who sponsored the review of the extension and fixed the found issues. The review was performed by Peter Niederlag, Sven Gähle and partly Rupert German.
Update your installations!
Greets,
Thomas
Waouuu ! Great, 1000 thanks, THomas. I'm already having great fun trimming the app. ;)...
Waouuu ! Great, 1000 thanks, THomas. I'm already having great fun trimming the app. ;)...
Hi, lottery closed. Tremendous number of attendees... ;-) Winners should have their licenses in t...
I was really happy to find this nice tool, over your blog. i used keepassx, but its really uncomfort...
Could anybody tell me where I can get more about setting Smarty with Eclipse ?