Tue. 13th May, 2008
It has been discovered that the extension Statistics (ke_stats) is vulnerable to Blind SQL Injection attacks. Also, a Cross Site Scripting issue has been found.
This is a companion discussion topic for the original entry at https://typo3.org/article/security-bulletin-typo3-20080513-4-multiple-vulnerabilities-in-extension-statistics-ke-stats/