Quick Login   
 
Register AdminFusion Tutorials
 
Featured Sponsors


One.com Domain and Hosting


Register
Forum of the Month
Australian Webmaster
fotm

A webmaster forum specifically catering for Australian site owners. We discuss site development, marketing and management issues.

Tag Cloud
Latest Threads
Forum Stats
8,073 Members
165,866 Posts
57 Users Online

Please welcome our newest member, masood!

Affiliates
Go Back AdminFusion » Getting Started » Software » Other Software » [MyBB News] MyBB 1.2.10 Security Update
Welcome to the AdminFusion. AdminFusion is the ultimate resource for forum administrators and moderators. With exclusive articles, interviews with the experts, free downloadable skins, and the revolutionary post exchange system - PostFusion, AdminFusion is the place to go for all of your forum needs.  By joining AdminFusion, you will become part of a thriving admin community and immediately gain access to all of these resources. Registration is fast, simple and absolutely free so please join us today!
Want more than our forums? Try these: Post Fusion Forum Matrix
Old 12-30-2007, 12:30 AM   #1

Title: Apprentice

Points: 4,964, Level: 20Points: 4,964, Level: 20Points: 4,964, Level: 20
Level up: 21%, 86 Points neededLevel up: 21%, 86 Points neededLevel up: 21%, 86 Points needed
Activity: 36%Activity: 36%Activity: 36%

Join Date: Sep 2005

Posts: 463

Industry News is on a distinguished road
 
 
Post [MyBB News] MyBB 1.2.10 Security Update

It has come to our attention that there may be a medium risk security vulnerability in MyBB 1.2.10 and earlier versions.

This vulnerability will allow a user to upload an undesirable avatar that even though they are told is invalid, is still left on the file system. Depending on some server configurations or when called via a web browser, this file may be executed either on the server side (as PHP) or on the client side (as HTML).

This is also a general flaw - when a user uploads an avatar and that doesn't return valid image dimensions, it won't be removed by MyBB.

Immediately we're releasing an update to MyBB 1.2.10 to fix this vulnerability/flaw. We recommend all users apply this fix to their forums as soon as possible.

Patching Your Installation
There are two ways to patch your existing installation of MyBB.

If you haven't made modifications to inc/functions_upload.php you can simply upload the attached version of the file overwriting your existing copy.

If you have modified inc/functions_upload.php, download the attached manual patching instructions and follow the instructions in the file to manually patch your board.

As of this post, the download on the MyBB website has also been updated.

Thank you to pepotiger for reporting thsi possible vulnerability to us.

More...
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

 
Posting Rules

Similar Threads
Thread Thread Starter Forum Replies Last Post
[MyBB News] MyBB Merge System 1.0 RC1 Released Industry News Other Software 4 12-17-2007 09:42 PM
[MyBB News] MyBB 1.2.10 Released - Maintenance Release Industry News Other Software 1 12-01-2007 06:49 PM
[MyBB News] MyBB 1.2.8 Released - Security & Maintenance Release Industry News Other Software 0 06-29-2007 11:54 AM
[MyBB News] MyBB 1.2.4 Released - Important Security Update Industry News Other Software 2 04-04-2007 12:38 PM
Chris B - MyBB Owner Ryan Interviews 9 08-23-2006 07:06 AM

AdminFusion

All times are GMT +1. The time now is 05:35 AM. Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0 © 2005-2008 AdminFusion - All Rights Reserved


From:
Title:

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72