2006-01-31, 10:38 AM
(This post was last modified: 2006-01-31, 09:11 PM by Chris Boulton.)
As some of you saw, when these forums were attacked, there has been the discovery of another serious security exploit in MyBB.
Soon after the boards were exploited, backups of the forum were restored and the discovery process began. Due to access logs being completely useless (Corrupt), I took to the code and found the potential vulnerability the attacker exploited.
Available immediately, we're announcing a security update for MyBB dubbed MyBB 1.03. This exploit affects ALL COPIES OF MYBB including previous versions. We recommend everybody update their board as soon as possible.
The update fixes the found SQL injection vulnerability (Critical) as well as several other medium priority vulnerabilities recently discovered. (Due to be released tomorrow anyway)
Affected files:
Updating Your Board
Please check your Admin CP to determine which MyBB version you are currently using.
If you are running MyBB 1.02
Any previous versions
MyBB Group
Soon after the boards were exploited, backups of the forum were restored and the discovery process began. Due to access logs being completely useless (Corrupt), I took to the code and found the potential vulnerability the attacker exploited.
Available immediately, we're announcing a security update for MyBB dubbed MyBB 1.03. This exploit affects ALL COPIES OF MYBB including previous versions. We recommend everybody update their board as soon as possible.
The update fixes the found SQL injection vulnerability (Critical) as well as several other medium priority vulnerabilities recently discovered. (Due to be released tomorrow anyway)
Affected files:
- global.php
- search.php
- usercp.php
- inc/functions.php (Version number change)
Updating Your Board
Please check your Admin CP to determine which MyBB version you are currently using.
If you are running MyBB 1.02
- Download the files in the attachment below and upload them to your forum.
Any previous versions
- Download the latest copy of MyBB from the MyBB website.
- Proceed with an upgrade as you usually would.
MyBB Group