Quick Login   
 
Register AdminFusion Tutorials
 
Featured Sponsors


One.com Domain and Hosting


Register
Forum of the Month
Australian Webmaster
fotm

A webmaster forum specifically catering for Australian site owners. We discuss site development, marketing and management issues.

Tag Cloud
Latest Threads
Forum Stats
8,073 Members
165,866 Posts
38 Users Online

Please welcome our newest member, masood!

Affiliates
Go Back AdminFusion » Getting Started » Software » Other Software » [MyBB News] MyBB 1.2.1 and 1.1.8 Security Update
Welcome to the AdminFusion. AdminFusion is the ultimate resource for forum administrators and moderators. With exclusive articles, interviews with the experts, free downloadable skins, and the revolutionary post exchange system - PostFusion, AdminFusion is the place to go for all of your forum needs.  By joining AdminFusion, you will become part of a thriving admin community and immediately gain access to all of these resources. Registration is fast, simple and absolutely free so please join us today!
Want more than our forums? Try these: Post Fusion Forum Matrix
Old 11-27-2006, 01:40 AM   #1

Title: Apprentice

Points: 4,964, Level: 20Points: 4,964, Level: 20Points: 4,964, Level: 20
Level up: 21%, 86 Points neededLevel up: 21%, 86 Points neededLevel up: 21%, 86 Points needed
Activity: 36%Activity: 36%Activity: 36%

Join Date: Sep 2005

Posts: 463

Industry News is on a distinguished road
 
 
Post [MyBB News] MyBB 1.2.1 and 1.1.8 Security Update

Hi,

It has come to our attention that a new vulnerability has been found in MyBB 1.2.1 which also affects MyBB 1.1.8 and all other previous versions of MyBB.

This vulnerability allows a hacker to upload a false GIF image which contains executable code which can then be used to obtain the authentication details for a logged in user viewing the page.

Immediately we're releasing a patch for both versions of MyBB which we're currently supporting. Both versions, 1.2.1 and 1.1.8 have also been updated on the MyBB site.

As a security precaution we also recommend that all administrators change their passwords.

MyBB 1.2.1 Patch
This patch is only for users running MyBB 1.2.1 or any release of the MyBB 1.2 series.

Please download the attached functions_upload.php and replace the copy in your inc/ directory.

If you wish to manually patch your board please download "attachments_121_manual_patch.txt" and follow the instructions in that file.

Please note that you should also start preparing for MyBB 1.2.2 as it will be released in the coming days.

More...
Reply With Quote
Old 11-27-2006, 02:13 AM   #2

Jolteon's Avatar

Title: Forum Junkie

Points: 18,292, Level: 41Points: 18,292, Level: 41Points: 18,292, Level: 41
Level up: 42%, 658 Points neededLevel up: 42%, 658 Points neededLevel up: 42%, 658 Points needed
Activity: 28%Activity: 28%Activity: 28%

Join Date: Feb 2006

Posts: 3,633

Location: Holmfirth, England

Jolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant future
Send a message via MSN to Jolteon  
 
I hope MyBB is as easy to update as vBulletin....
__________________
http://EasyToHide.Info
Visit my proxy for anonymous surfing!

Reply With Quote
Old 11-27-2006, 12:42 PM   #3

Belloman's Avatar

Title: Apprentice

Points: 3,643, Level: 17Points: 3,643, Level: 17Points: 3,643, Level: 17
Level up: 18%, 207 Points neededLevel up: 18%, 207 Points neededLevel up: 18%, 207 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: May 2006

Posts: 431

Location: Central Ohio, USA

Belloman is a name known to allBelloman is a name known to allBelloman is a name known to allBelloman is a name known to allBelloman is a name known to allBelloman is a name known to all
 
 
That patch is really easy... change one line of code! It's because that's a security patch. For 1.2.2, you'll have to upload changed files - it'll be a bugfix release
__________________
RCTgo - SHARE. DISCUSS. EXPLORE.
Justin S. / MyBB Wiki Lead / RCTgo.net
Reply With Quote
Old 11-27-2006, 12:44 PM   #4

Jolteon's Avatar

Title: Forum Junkie

Points: 18,292, Level: 41Points: 18,292, Level: 41Points: 18,292, Level: 41
Level up: 42%, 658 Points neededLevel up: 42%, 658 Points neededLevel up: 42%, 658 Points needed
Activity: 28%Activity: 28%Activity: 28%

Join Date: Feb 2006

Posts: 3,633

Location: Holmfirth, England

Jolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant futureJolteon has a brilliant future
Send a message via MSN to Jolteon  
 
Oh i have patched it OK, i am more worried about freaking up the upgrade, I'm too used to vBulletin now...
__________________
http://EasyToHide.Info
Visit my proxy for anonymous surfing!

Reply With Quote
Old 11-27-2006, 02:26 PM   #5

Reiji Kurosaky's Avatar

Title: Member

Points: 1,849, Level: 11Points: 1,849, Level: 11Points: 1,849, Level: 11
Level up: 12%, 1 Points neededLevel up: 12%, 1 Points neededLevel up: 12%, 1 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: Jul 2006

Posts: 135

Location: Dominican Republic

Reiji Kurosaky will become famous soon enough
Send a message via Yahoo to Reiji Kurosaky  
 
This is an easy one. I have patched my board.
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

 
Posting Rules

Similar Threads
Thread Thread Starter Forum Replies Last Post
MyBB 1.2.1 Released - Maintenance & Security Update Release Belloman Other Software 0 09-27-2006 11:52 PM
MyBB 1.1.8 Released Belloman Other Software 2 08-31-2006 12:41 PM

AdminFusion

All times are GMT +1. The time now is 04:44 AM. Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0 © 2005-2008 AdminFusion - All Rights Reserved


From:
Title:

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72