TYPO3 prior to 4.2.13, 4.3.x prior to 4.3.4 and 4.4.x prior to 4.4.1 allows XSS and Open Redirection in the frontend login box.
typo3 typo3