Subscribe to Acqal

Got Thoughts? Write Us!

Contact
Request
Validate

Approved TYPO3 Agency

Acqal is an approved TYPO3 agency focusing on support, training and website migration.

This means that we...

  • are available on TYPO3.org
  • make substantial contributions to TYPO3 teams
  • are registered as business members of the TYPO3 Association
  • have completed more than four TYPO3 projects
  • have proven our technical abilities with quality TYPO3 extensions
  • use TYPO3 for our own website

Acqal is a TYPO3 Association Business Member

Popular Blog Posts

Blog Topics

Virgil on Twitter

Please wait while virgilhuston tweets load Twitter is loading

Recent Blog Posts

Blog Archives

Acqal's TYPO3 Clients Protected Within 8 Hours of Security Notice

Tuesday, February 10, 2009 11:10 PM EST

By: Michael Cannon

voting in progress Submitting your vote...
Rating: 1.0 of 5. 1 vote(s).
Click the rating bar to rate this item.

Within 8-hours of TYPO3 Security Bulletin TYPO3-SA-2009-002 being released, Acqal's team had their active client TYPO3 systems updated. Did your TYPO3 CMS provider do the same?

The security bulletin contained a critical fix to an 

Information Disclosure vulnerability in jumpUrl mechanism, used to track access on web pages and provided files, allows a remote attacker to read arbitrary files on a host.

The expected value of a mandatory hash secret, intended to invalidate such requests, is exposed to remote users allowing them to bypass access control by providing the correct value.

There's no authentication required to exploit this vulnerability. The vulnerability allows to read any file, the web server user account has access to.

If your TYPO3 provider hasn't updated your TYPO3 system yet, contact Acqal for immediate help. Don't let this critical issue go unchecked. Most systems are fixed in under 30 minutes of effort.

Keywords:

  • security,patch,update

Please Share This Post

Tweet thisRedditBookmark on deliciousStumble thisShare on Facebook

Send this article via email to your friends and peers.

Leave a Comment

Add comment

* - required field







Notify me when a new comment is added.