Irish SEO,  Marketing & Webmaster Discussion
 

 

Go Back   Irish SEO, Marketing & Webmaster Discussion > Webmaster Help > Server / Technical Administration Tips and Queries > Security


Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 09-01-2008, 09:03 AM
blacknight's Avatar
Web Slave
 
Join Date: Jan 2006
Location: Ireland
Posts: 5,838
blacknight is just really niceblacknight is just really niceblacknight is just really niceblacknight is just really nice
Send a message via ICQ to blacknight Send a message via AIM to blacknight Send a message via MSN to blacknight
Exclamation Photopost VBGallery Security Hole

Just got this:
This bulletin affects all versions of PhotoPost vBGallery prior to 2.4.2
but does not affect PhotoPost Pro, ReviewPost, or PhotoPost Classifieds.

We recently became aware of a new exploit that hackers have created in
order to upload and attempt to execute php scripts on a webserver using
vBGallery. The exploit essentially involves uploading a PHP script
disguised as an image file, using a filename that contains a ".php.gif", "
php.wmv" or a similar file extension in order to manipulate or trick the
Apache webserver into executing the script as a PHP program. Ultimately,
this is a security flaw in the Apache webserver and has the potential to
affect any software that handles user file uploads, not just vBGallery, but
we have patched vBGallery and released 2.4.2 to prevent this issue from
occuring.

Please visit our forum to read the complete bulletin, see instructions on
updating to vBGallery 2.4.2 for vBulletin 3.6 and 3.7 (or manually patching
older versions of vBGallery against this potential exploit), and read about
the provided "clean.php" scanner script used to look for potential

".php.gif" type file uploads:
PhotoPost vBGallery Important Security Bulletin - PhotoPost Community
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Security with open source aaron_kenny Security 4 05-03-2008 11:34 PM


All times are GMT +1. The time now is 10:01 PM.


Powered by: vBulletin Version 3.7.2, Copyright ©2000 - 2008, Jelsoft Enterprises Limited.

Search Engine Friendly URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56