Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: TYPO3 SQL Injection vunerabilitie

Re: TYPO3 SQL Injection vunerabilitie

From: Michael Shigorin <mike_at_osdn.org.ua>
Date: Fri, 4 Mar 2005 18:45:33 +0200

On Fri, Mar 04, 2005 at 12:06:37AM +0100, Sebastian Wolfgarten wrote:
> I am pretty sure Fabian (Neonomicus) meant *every link* (or
> site) generated by Typo3, didn't he?

Even if he did, it would be just as incorrect as the original
Subject.

> @Fabian (Neonomicus): Could you please provide more details
> about the vulnerability you've discoveredl? By the way did you
> give the Typo3 guys *enough* time to respond???

Most likely it was some weird way of contacting them in the
first place: posting the message to BTS resulted in an updated
extension version being published within some 5 hours, security
announce on the website ("Severity: high") and a reminder on
contact address (typo3-project-security>lists.netfielders.de).

PS: when choosing "the next CMS", one of our considerations was
virtually empty bugtraq coverage (with the code being public
since 2000 and used on quite a few sites). Go figure :-)

-- 
 ---- WBR, Michael Shigorin <mike_at_altlinux.ru>
  ------ Linux.Kiev http://www.linux.kiev.ua/

  • application/pgp-signature attachment: stored
Received on Mar 04 2005
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos