MyBB Community Forums

Full Version: Urgent Bug!
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
A member just joined my forum, automatically made himself VIP, changed his registration date to 2007, gave himself over 100 reputation and changed his post count to 700.

This seems like he's had Admin CP access, but I've been in ACP the whole time, no one was in there. What about PHPMYAdmin, could these changes be done from there?
Absolutely! These changes were done from phpmyadmin or from a script in your account!
Yeah it can't have been via the ACP as you can't change the registration date via the ACP. There aren't any known vulnerabilities in 1.6; check your file system for any non-MyBB files, run the file verification tool in the ACP to check no files have been edited, and look in access logs to see what they did and where.