A webmaster forum specifically catering for Australian site owners. We discuss site development, marketing and management issues.
Please welcome our newest member, masood!
Spice up your web site with the ultimate community message board solution!
Fake Id'sGet fake Id's made right now!
vBSEOSearch Engine Optimization for your VBulletin Forum.
AdminFusion
»
[MyBB News] MyBB 1.2.10 Security Update
| | #1 |
| | |||||
| Title: Apprentice Join Date: Sep 2005 Posts: 463 ![]() | It has come to our attention that there may be a medium risk security vulnerability in MyBB 1.2.10 and earlier versions. This vulnerability will allow a user to upload an undesirable avatar that even though they are told is invalid, is still left on the file system. Depending on some server configurations or when called via a web browser, this file may be executed either on the server side (as PHP) or on the client side (as HTML). This is also a general flaw - when a user uploads an avatar and that doesn't return valid image dimensions, it won't be removed by MyBB. Immediately we're releasing an update to MyBB 1.2.10 to fix this vulnerability/flaw. We recommend all users apply this fix to their forums as soon as possible. Patching Your Installation There are two ways to patch your existing installation of MyBB. If you haven't made modifications to inc/functions_upload.php you can simply upload the attached version of the file overwriting your existing copy. If you have modified inc/functions_upload.php, download the attached manual patching instructions and follow the instructions in the file to manually patch your board. As of this post, the download on the MyBB website has also been updated. Thank you to pepotiger for reporting thsi possible vulnerability to us. More... | ||||
| |
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| Display Modes | |
| |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| [MyBB News] MyBB Merge System 1.0 RC1 Released | Industry News | Other Software | 4 | 12-17-2007 09:42 PM |
| [MyBB News] MyBB 1.2.10 Released - Maintenance Release | Industry News | Other Software | 1 | 12-01-2007 06:49 PM |
| [MyBB News] MyBB 1.2.8 Released - Security & Maintenance Release | Industry News | Other Software | 0 | 06-29-2007 11:54 AM |
| [MyBB News] MyBB 1.2.4 Released - Important Security Update | Industry News | Other Software | 2 | 04-04-2007 12:38 PM |
| Chris B - MyBB Owner | Ryan | Interviews | 9 | 08-23-2006 07:06 AM |
