<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Lacisoft&#039;s &#187; vulnerability</title>
	<atom:link href="http://www.lacisoft.com/blog/tag/vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.lacisoft.com/blog</link>
	<description>SELECT * FROM lacisoft</description>
	<lastBuildDate>Mon, 30 Jan 2012 17:42:20 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Critical security issue in Typo3 core &#8211; all versions</title>
		<link>http://www.lacisoft.com/blog/2009/02/10/critical-security-issue-in-typo3-core-all-versions/</link>
		<comments>http://www.lacisoft.com/blog/2009/02/10/critical-security-issue-in-typo3-core-all-versions/#comments</comments>
		<pubDate>Tue, 10 Feb 2009 12:27:05 +0000</pubDate>
		<dc:creator>lacisoft</dc:creator>
				<category><![CDATA[CMS]]></category>
		<category><![CDATA[Frameworks]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[web development]]></category>
		<category><![CDATA[3.2.6]]></category>
		<category><![CDATA[issue]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[typo3]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.lacisoft.com/blog/?p=99</guid>
		<description><![CDATA[A very serious security issue has been discovered in Typo3 core, all versions including 4.2.5 are affected. According to some this is the most critical security breach in Typo3 ever discovered. The vulnerability allows attackers to &#8220;download the contents of any file on the server, i.e. typo3conf/localconf.php, which holds both install tool password alongside database username [...]
Related posts:<ol>
<li><a href='http://www.lacisoft.com/blog/2011/12/06/new-typo3-security-guide/' rel='bookmark' title='New TYPO3 Security Guide'>New TYPO3 Security Guide</a></li>
<li><a href='http://www.lacisoft.com/blog/2008/12/11/googles-browser-security-handbook/' rel='bookmark' title='Google&#8217;s browser security handbook'>Google&#8217;s browser security handbook</a></li>
<li><a href='http://www.lacisoft.com/blog/2009/10/20/older-powermail-versions-and-config-absrefprefix/' rel='bookmark' title='Older powermail versions and config.absRefPrefix'>Older powermail versions and config.absRefPrefix</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>A very serious security issue has been discovered in Typo3 core, all versions including 4.2.5 are affected. According to some this is the most critical security breach in Typo3 ever discovered. The vulnerability allows attackers to &#8220;<em>download the contents of any file on the server, i.e. typo3conf/localconf.php, which holds both install tool password alongside database username and password</em>&#8220;.</p>
<p>There is a fix, Typo3 version 4.2.6. which is available as of today. And there are also other solutions and patches, read carefully the <a href="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-002/">security bulletin</a> and fix your Typo3 installation if you care for your files, passwords and other data on your webserver.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.lacisoft.com%2Fblog%2F2009%2F02%2F10%2Fcritical-security-issue-in-typo3-core-all-versions%2F&amp;title=Critical%20security%20issue%20in%20Typo3%20core%20%26%238211%3B%20all%20versions" id="wpa2a_2"><img src="http://www.lacisoft.com/blog/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p><p>Related posts:<ol>
<li><a href='http://www.lacisoft.com/blog/2011/12/06/new-typo3-security-guide/' rel='bookmark' title='New TYPO3 Security Guide'>New TYPO3 Security Guide</a></li>
<li><a href='http://www.lacisoft.com/blog/2008/12/11/googles-browser-security-handbook/' rel='bookmark' title='Google&#8217;s browser security handbook'>Google&#8217;s browser security handbook</a></li>
<li><a href='http://www.lacisoft.com/blog/2009/10/20/older-powermail-versions-and-config-absrefprefix/' rel='bookmark' title='Older powermail versions and config.absRefPrefix'>Older powermail versions and config.absRefPrefix</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.lacisoft.com/blog/2009/02/10/critical-security-issue-in-typo3-core-all-versions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

