Quick Login   
 
Register AdminFusion Tutorials
 
Featured Sponsors


One.com Domain and Hosting


Register
Forum of the Month
Australian Webmaster
fotm

A webmaster forum specifically catering for Australian site owners. We discuss site development, marketing and management issues.

Tag Cloud
Latest Threads
Forum Stats
8,073 Members
165,866 Posts
47 Users Online

Please welcome our newest member, masood!

Affiliates
Go Back AdminFusion » Getting Started » Software » Other Software » [MyBB News] MyBB 1.2.11 Released - IMPORTANT Security Update
Welcome to the AdminFusion. AdminFusion is the ultimate resource for forum administrators and moderators. With exclusive articles, interviews with the experts, free downloadable skins, and the revolutionary post exchange system - PostFusion, AdminFusion is the place to go for all of your forum needs.  By joining AdminFusion, you will become part of a thriving admin community and immediately gain access to all of these resources. Registration is fast, simple and absolutely free so please join us today!
Want more than our forums? Try these: Post Fusion Forum Matrix
Old 01-08-2008, 01:22 PM   #1

Title: Apprentice

Points: 4,964, Level: 20Points: 4,964, Level: 20Points: 4,964, Level: 20
Level up: 21%, 86 Points neededLevel up: 21%, 86 Points neededLevel up: 21%, 86 Points needed
Activity: 36%Activity: 36%Activity: 36%

Join Date: Sep 2005

Posts: 463

Industry News is on a distinguished road
 
 
Post [MyBB News] MyBB 1.2.11 Released - IMPORTANT Security Update

MyBB 1.2.11 is a security update to the MyBB 1.2 series. It fixes two HIGH risk security vulnerabilities and a few low risk vulnerabilities reported in MyBB earlier today. We recommend everybody upgrades to this release immediately or patches their boards with the manual patching instructions below.

Both high risk vulnerabilities have been observed to have been used and exploited by malicious users already.

This security update fixes:

[HIGH RISK] Remote execution vulnerability in forumdisplay.php allowing arbitrary file system access and code execution.
[HIGH RISK] Remote execution vulnerability in search.php allowing arbitrary file system access and code execution.
[LOW RISK] SQL injection via moderation features. (Note: This requires the attacker have a moderator account)
[LOW RISK] SQL injection via the Admin CP and approve join requests feature. (Note: This requires the attacker have an administrator account)


Thank you to both koziolek and waraxe for reporting these vulnerabilities.

These vulnerabilities affect MyBB 1.2.10 and previous releases of MyBB 1.2. Older versions of MyBB may also be affected

MyBB 1.2.10 to MyBB 1.2.11 Patch
This patch is only for users running MyBB 1.2.10. If you are running any other version of the MyBB 1.2 series then please download MyBB 1.2.11 from the MyBB site and update to it.

Please download the attached ZIP archive and replace the files in your forum directory with those from the ZIP archive.

[attachment=8398]

If you wish to manually patch your board please download "mybb_1211_patches.txt" and follow the instructions in that file.

[attachment=8399]

For the upgrade of 1.2.10 to 1.2.11, the upgrader is NOT required -- just replace the files (or modify them as per the manual patch instructions) and you will be set.

Want us to patch your installation?
Due to the severe nature of these vulnerabilities, we urge all users to upgrade their forums as soon as they read this message.

If you're unsure of how, don't have the time or need assistance patching your board then please contact one of the staff mentioned below. We'll patch your board for you as soon as we can.

Note: This is only for patching your board for this vulnerability. We cannot upgrade your forums from other major releases. We also require your FTP/server details to perform the upload.

Staff performing upgrades:

Chris Boulton


Reporting MyBB security vulnerabilities
If you think you've found a vulnerability in MyBB, we advise you not to publicly post it on these forums or publicly release information about it elsewhere until we've had time to prepare and release patch.

As always, you can send through security related messages on the MyBB website from the Contact Us page.

More...
Reply With Quote
Old 01-09-2008, 03:37 AM   #2

Belloman's Avatar

Title: Apprentice

Points: 3,643, Level: 17Points: 3,643, Level: 17Points: 3,643, Level: 17
Level up: 18%, 207 Points neededLevel up: 18%, 207 Points neededLevel up: 18%, 207 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: May 2006

Posts: 431

Location: Central Ohio, USA

Belloman is a name known to allBelloman is a name known to allBelloman is a name known to allBelloman is a name known to allBelloman is a name known to allBelloman is a name known to all
 
 
Upgraded from 1.2.9 () without a problem... just had to reapply my template conditionals mod...
__________________
RCTgo - SHARE. DISCUSS. EXPLORE.
Justin S. / MyBB Wiki Lead / RCTgo.net
Reply With Quote
Old 01-09-2008, 07:23 AM   #3
Jon

Jon is offline

Jon's Avatar

Title: Member

Points: 2,183, Level: 13Points: 2,183, Level: 13Points: 2,183, Level: 13
Level up: 14%, 267 Points neededLevel up: 14%, 267 Points neededLevel up: 14%, 267 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: Apr 2006

Posts: 114

Location: California

Jon has a spectacular aura aboutJon has a spectacular aura about
Send a message via AIM to Jon  
 
Good thing I caught this when I did. Thanks MyBB team.
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

 
Posting Rules

Similar Threads
Thread Thread Starter Forum Replies Last Post
[MyBB News] MyBB 1.2.10 Security Update Industry News Other Software 0 12-30-2007 12:30 AM
[MyBB News] MyBB Merge System 1.0 RC1 Released Industry News Other Software 4 12-17-2007 09:42 PM
[MyBB News] MyBB 1.2.10 Released - Maintenance Release Industry News Other Software 1 12-01-2007 06:49 PM
[MyBB News] MyBB 1.2.8 Released - Security & Maintenance Release Industry News Other Software 0 06-29-2007 11:54 AM
[MyBB News] MyBB 1.2.4 Released - Important Security Update Industry News Other Software 2 04-04-2007 12:38 PM

AdminFusion

All times are GMT +1. The time now is 05:00 AM. Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0 © 2005-2008 AdminFusion - All Rights Reserved


From:
Title:

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72