MyBB 1.03 Released - Security Update
#1
As some of you saw, when these forums were attacked, there has been the discovery of another serious security exploit in MyBB.

Soon after the boards were exploited, backups of the forum were restored and the discovery process began. Due to access logs being completely useless (Corrupt), I took to the code and found the potential vulnerability the attacker exploited.

Available immediately, we're announcing a security update for MyBB dubbed MyBB 1.03. This exploit affects ALL COPIES OF MYBB including previous versions. We recommend everybody update their board as soon as possible.

The update fixes the found SQL injection vulnerability (Critical) as well as several other medium priority vulnerabilities recently discovered. (Due to be released tomorrow anyway)

Affected files:
  • global.php
  • search.php
  • usercp.php
  • inc/functions.php (Version number change)

Updating Your Board
Please check your Admin CP to determine which MyBB version you are currently using.

If you are running MyBB 1.02
  • Download the files in the attachment below and upload them to your forum.
You do NOT need to run the upgrade scripts.

Any previous versions
  • Download the latest copy of MyBB from the MyBB website.
  • Proceed with an upgrade as you usually would.
If you are running MyBB 1.01, or MyBB 1.0 then you do not need to run any upgrade scripts.

MyBB Group


Attached Files
.zip   mybb_103_changed_files.zip (Size: 33.47 KB / Downloads: 1,412)


Messages In This Thread
MyBB 1.03 Released - Security Update - by - 01-31-2006, 10:38 AM
RE: MyBB 1.03 Released - Security Update - by - 01-31-2006, 10:40 AM
RE: MyBB 1.03 Released - Security Update - by - 01-31-2006, 10:56 AM
RE: MyBB 1.03 Released - Security Update - by - 01-31-2006, 11:10 AM

Forum Jump:


Users browsing this thread: 1 Guest(s)