Affiliation/Organization: TYPO3 Security Team

Other Affiliations

Creditees Affiliated with TYPO3 Security Team have also affiliated with:

TYPO3 - Core Team (1)

Website: http://typo3.org/teams/security/

Creditees currently or formerly associated with TYPO3 Security Team (8):
(ordered by association date)

Known SinceNameVulns Through Affiliation
2010-02-01Georg Ringer25
2010-03-16Marcus Krause6
2010-07-28Helmut Hummel12
2012-02-03Sebastian Böttger2
2012-02-23Franz G. Jahn12
2012-03-28Markus Bucher3
2012-03-28Oliver Klee3
2012-06-07Susanne Moog1

Disclosed Vulnerabilities (63):

Discl. DateOSVDB IDCVE IDCrediteesTitle
2013-02-19 90414 Oliver Klee
Static Info Tables Extension for TYPO3 Unspecified XSS
2013-01-28 92968 Franz G. Jahn
Attac Petition (attacpetition) Extension for TYPO3 Unspecified SQL Injection
2013-01-28 92971 Franz G. Jahn
Twitter Auth Service (twitter_auth) Extension for TYPO3 Unspecified Authentication Bypass
2013-01-28 92972 Franz G. Jahn
From a csv-file to a html-table (kk_csv2table) Extension for TYPO3 Unspecified Arbitrary File Access
2013-01-28 92974 Georg Ringer
UserTask Center, Messaging (sys_messages) Extension for TYPO3 Unspecified XSS
2013-01-28 92973 Georg Ringer
Javascript and CSS Optimizer (js_css_optimizer) Extension for TYPO3 Unspecified XSS
2013-01-11 89130 Franz G. Jahn
T3 Mootools (t3mootools) Extension for TYPO3 unserialize() Call Remote PHP Code Execution
2013-01-11 89128 Marcus Krause
1-Click-Login (oneclicklogin) Extension for TYPO3 Unspecified XSS
2012-08-15 84774 2012-3531 Georg Ringer
TYPO3 Install Tool Unspecified XSS
2012-08-15 84771 2012-3528 Pavel Vaysband
Markus Bucher
Susanne Moog
Jan Bednarik
TYPO3 Backend Unspecified XSS
2012-08-08 84524 Helmut Hummel
powermail Extension for TYPO3 Unspecified Remote PHP Code Execution
2012-08-08 84523 Helmut Hummel
powermail Extension for TYPO3 Unspecified XSS
2012-08-08 84525 Helmut Hummel
powermail Extension for TYPO3 Unspecified SQL Injection
2012-06-07 87753 Susanne Moog
Basic SEO Features (seo_basics) for TYPO3 Unspecified SQL Injection
2012-06-07 87752 Oliver Klee
Ameos Formidable (ameos_formidable) for TYPO3 Unspecified XSS
2012-05-30 82695 Georg Ringer
powermail Extension for TYPO3 Unspecified XSS
2012-04-17 81775 2012-2112 Helmut Hummel
TYPO3 Exception Handler XSS
2012-03-28 80759 2012-1605 Helmut Hummel
TYPO3 Extbase Framework Missing HMAC Arbitrary Object Unserialization Weakness
2012-03-28 80760 2012-1606 Oliver Klee
Georg Ringer
TYPO3 Backend Unspecified XSS
2012-03-28 80857 Franz G. Jahn
WhoisLookup (fe_whois) Extension for TYPO3 Unspecified Remote Code Execution
2012-03-28 80858 Helmut Hummel
General data display (general_data_display) Extension for TYPO3 Unspecified XSS
2012-03-28 80859 Helmut Hummel
General data display (general_data_display) Extension for TYPO3 Unspecified SQL Injection
2012-03-28 80860 Franz G. Jahn
TCFacebook Connect (tc_fbconnect) Extension for TYPO3 Unspecified Authentication Bypass
2012-03-28 80861 Franz G. Jahn
Easy Login and Register with OpenID (FE) (dix_easylogin) Extension for TYPO3 Unspecified Authentication Bypass
2012-03-28 80862 Franz G. Jahn
Ajado Facebook Connect (ajado_facebook) Extension for TYPO3 Unspecified Authentication Bypass
2012-03-28 80863 Franz G. Jahn
Facebook Connect to TYPO3 (facebook2t3) Extension for TYPO3 Unspecified Authentication Bypass
2012-03-28 80864 Franz G. Jahn
Social Login to TYPO3 (sociallogin2t3) Extension for TYPO3 Unspecified Authentication Bypass
2012-03-28 80710 Georg Ringer
additional_reports Extension for TYPO3 Unspecified Traversal Arbitrary File Access
2012-03-28 87734 2012-5889 David Henninger
Oliver Meyfarth
Markus Bucher
powermail Extension for TYPO3 Unspecified XSS
2012-03-28 87733 2012-5888 Markus Bucher
Basic SEO Features (seo_basics) Extension for TYPO3 Unspecified XSS
2012-02-23 79482 Georg Ringer
TC BE User Admin (tc_beuser) Extension for TYPO3 Unspecified XSS
2012-02-23 79483 Georg Ringer
Predigtsammlung (an_predigten) Extension for TYPO3 Unspecified SQL Injection
2012-02-23 79484 Georg Ringer
PDF Controller (pdfcontroller) Extension for TYPO3 Unspecified Remote Code Execution
2012-02-23 79485 Georg Ringer
PDF Controller (pdfcontroller) Extension for TYPO3 Unspecified Information Disclosure
2012-02-23 87732 2012-5890 Christian Boltz
Franz G. Jahn
Front End User Registration (sr_feuser_register) Extension for TYPO3 Edit Perspective Cleartext User Password Disclosure
2012-02-23 87731 2012-5890 Christian Boltz
Franz G. Jahn
Front End User Registration (sr_feuser_register) Extension for TYPO3 Autologin Redirect Cleartext Credential Disclosure
2012-02-03 78785 2012-1072 Georg Ringer
Category-System Extension for TYPO3 Unspecified SQL Injection
2012-02-03 78787 2012-1076 Sebastian Böttger
Documents download (rtg_files) Extension for TYPO3 Unspecified XSS
2012-02-03 78784 2012-1073 Georg Ringer
Category-System Extension for TYPO3 Unspecified XSS
2012-02-03 78788 2012-1075 Sebastian Böttger
Documents download (rtg_files) Extension for TYPO3 Unspecified SQL Injection
2012-02-02 78750 2011-5079 Marcus Krause
Modern FAQ Extension for TYPO3 Unspecified Arbitrary Site Redirect
2012-02-02 78790 2012-1077 Georg Ringer
Post data records to facebook Extension for TYPO3 Unspecified SQL Injection
2012-02-02 78794 2012-1080 Georg Ringer
Euro Calculator Extension for TYPO3 Unspecified XSS
2012-02-02 78795 2012-1081 Georg Ringer
Yet another Google search Extension for TYPO3 Unspecified XSS
2012-02-02 78798 2012-1084 Helmut Hummel
BE User Switch Extension for TYPO3 Unspecified XSS
2012-02-02 78799 2012-1085 Helmut Hummel
BE User Switch Extension for TYPO3 Unspecified Information Disclosure
2012-02-02 78749 2012-1070 Marcus Krause
Modern FAQ Extension for TYPO3 Unspecified XSS
2012-02-02 78789 2012-1087 Georg Ringer
Post data records to facebook Extension for TYPO3 Unspecified XSS
2012-02-02 78800 2011-5080 Georg Ringer
Additional TCA Forms Extension for TYPO3 lib/class.tx_jftcaforms_tceFunc.php Unspecified XSS
2012-01-16 78791 2012-1078 Georg Ringer
System Utilities (sysutils) Extension for TYPO3 Unspecified Information Disclosure
2011-08-25 87705 Georg Ringer
Questionaire (pbsurvey) Extension for TYPO3 Unspecified XSS
2011-03-15 71170 Georg Ringer
Direct Mail Extension for TYPO3 Unspecified XSS
2011-03-15 71171 Georg Ringer
Direct Mail Extension for TYPO3 Unspecified SQL Injection
2010-12-17 70122 2010-5098
2012-2343
Helmut Hummel
TYPO3 FORM Content Object Unspecified XSS
2010-12-16 70116 2010-5104
2012-2349
Marcus Krause
TYPO3 escapeStrForLike() Function Wildcard Injection Records Disclosure
2010-10-06 68594 Daniel Sloof
Helmut Hummel
Susanne Moog
TYPO3 Admin Panel Unspecified XSS
2010-07-28 66880 Marc Bastian Heinrichs
Steffen Kamper
Helmut Hummel
TYPO3 Backend Unspecified Editing Forms SQL Injection
2010-07-28 66868 Marcus Krause
TYPO3 Install Tool Unspecified Session Fixation
2010-03-16 63038 2010-1022 Marcus Krause
t3sec_saltedpw Extension for TYPO3 Unspecified Extension Bypass
2010-03-16 63037 2010-1023 Georg Ringer
UserTask Center, Recent Extension for TYPO3 Unspecified XSS
2010-02-01 87669 Georg Ringer
Surprise Calendar (ml_surprisecalendar) Extension for TYPO3 Unspecified SQL Injection
2010-02-01 87681 Georg Ringer
Download Manager (spr_downloadmanager) Extension for TYPO3 Unspecified Information Disclosure
2010-02-01 87665 Georg Ringer
Event Manager Extension for TYPO3 Unspecified SQL Injection

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2002 - 2013 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use