TYPO3 News

news.typo3.org: The TYPO3 news resource
It has been discovered that the extension Statistics (ke_stats) is vulnerable to Blind SQL Injection attacks. Also, a Cross Site Scripting issue has been found.
It has been discovered that the extension Event Database (rlmp_eventdb) is susceptible to Cross Site Scripting (XSS) attacks.
It has been discovered that the extension Questionaire (pbsurvey) is susceptible to Cross Site Scripting (XSS) attacks.
It has been discovered that the extension WT Gallery (wt_gallery) is susceptible to Path Traversal and Cross Site Scripting (XSS) attacks. Besides that, it may disclose sensitive information.
For all of you who are not that deeply involved in the making of TYPO3 v5, I have collected the most important bits of last month's activities.
It has been discovered that the extension powermail is susceptible to Cross Site Scripting (XSS) attacks.
It has been discovered that the extension MailformPlus (th_mailformplus) is susceptible to Cross Site Scripting (XSS) attacks and allows Remote Code Execution.
BAAR - The TYPO3 Association 4.x Development Team has released a new version of their very successful open source project. TYPO3 has been downloaded over 3.000.000 times from Sourceforge.org which...
Lightning does hit twice! T3BOARD returns to LAAX from the 22. to the 29. of march 2009!
The core team is proud to announce the second Release Candidate of TYPO3 version 4.2. We now think that we do have all blockers for a final release fixed so that if no critical bugs are found in this...