Quick Login   
 
Register AdminFusion Tutorials Post Fusion Forum Matrix
 
Go Back AdminFusion » Software & Tech » Software » Other Software » [MyBB News] MyBB 1.2.11 Released - IMPORTANT Security Update
Reply
 
LinkBack
Old 01-08-2008, 12:22 PM   #1
Forum Guru
 
Join Date: Sep 2005
Posts: 8,309
Industry News is on a distinguished road
Post [MyBB News] MyBB 1.2.11 Released - IMPORTANT Security Update

MyBB 1.2.11 is a security update to the MyBB 1.2 series. It fixes two HIGH risk security vulnerabilities and a few low risk vulnerabilities reported in MyBB earlier today. We recommend everybody upgrades to this release immediately or patches their boards with the manual patching instructions below.

Both high risk vulnerabilities have been observed to have been used and exploited by malicious users already.

This security update fixes:

[HIGH RISK] Remote execution vulnerability in forumdisplay.php allowing arbitrary file system access and code execution.
[HIGH RISK] Remote execution vulnerability in search.php allowing arbitrary file system access and code execution.
[LOW RISK] SQL injection via moderation features. (Note: This requires the attacker have a moderator account)
[LOW RISK] SQL injection via the Admin CP and approve join requests feature. (Note: This requires the attacker have an administrator account)


Thank you to both koziolek and waraxe for reporting these vulnerabilities.

These vulnerabilities affect MyBB 1.2.10 and previous releases of MyBB 1.2. Older versions of MyBB may also be affected

MyBB 1.2.10 to MyBB 1.2.11 Patch
This patch is only for users running MyBB 1.2.10. If you are running any other version of the MyBB 1.2 series then please download MyBB 1.2.11 from the MyBB site and update to it.

Please download the attached ZIP archive and replace the files in your forum directory with those from the ZIP archive.

[attachment=8398]

If you wish to manually patch your board please download "mybb_1211_patches.txt" and follow the instructions in that file.

[attachment=8399]

For the upgrade of 1.2.10 to 1.2.11, the upgrader is NOT required -- just replace the files (or modify them as per the manual patch instructions) and you will be set.

Want us to patch your installation?
Due to the severe nature of these vulnerabilities, we urge all users to upgrade their forums as soon as they read this message.

If you're unsure of how, don't have the time or need assistance patching your board then please contact one of the staff mentioned below. We'll patch your board for you as soon as we can.

Note: This is only for patching your board for this vulnerability. We cannot upgrade your forums from other major releases. We also require your FTP/server details to perform the upload.

Staff performing upgrades:

Chris Boulton


Reporting MyBB security vulnerabilities
If you think you've found a vulnerability in MyBB, we advise you not to publicly post it on these forums or publicly release information about it elsewhere until we've had time to prepare and release patch.

As always, you can send through security related messages on the MyBB website from the Contact Us page.

More...
Industry News is offline   Reply With Quote
Old 01-09-2008, 02:37 AM   #2
Apprentice
 
Belloman's Avatar
 
Join Date: May 2006
Location: Central Ohio, USA
Posts: 431
Belloman is a name known to allBelloman is a name known to allBelloman is a name known to allBelloman is a name known to allBelloman is a name known to allBelloman is a name known to all
Upgraded from 1.2.9 () without a problem... just had to reapply my template conditionals mod...
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

Justin S. / MyBB Wiki Lead /
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.

Belloman is offline   Reply With Quote
Old 01-09-2008, 06:23 AM   #3
Jon
Member
 
Jon's Avatar
 
Join Date: Apr 2006
Location: California
Posts: 128
Jon has a spectacular aura aboutJon has a spectacular aura about
Send a message via AIM to Jon
Good thing I caught this when I did. Thanks MyBB team.
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.


To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
Jon is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

 
Posting Rules

Similar Threads
Thread Thread Starter Forum Replies Last Post
[MyBB News] MyBB 1.2.10 Security Update Industry News Other Software 0 12-29-2007 11:30 PM
[MyBB News] MyBB Merge System 1.0 RC1 Released Industry News Other Software 4 12-17-2007 08:42 PM
[MyBB News] MyBB 1.2.10 Released - Maintenance Release Industry News Other Software 1 12-01-2007 05:49 PM
[MyBB News] MyBB 1.2.8 Released - Security & Maintenance Release Industry News Other Software 0 06-29-2007 10:54 AM
[MyBB News] MyBB 1.2.4 Released - Important Security Update Industry News Other Software 2 04-04-2007 11:38 AM

AdminFusion

All times are GMT +1. The time now is 08:46 PM. Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

© 2009 AdminFusion | Advertising Opportunities | Legal | A member of the Crowdgather Forum Community
 
From:
Title:

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77