There is a serious exploit in phpBB that requires immediate patch.

Patch

If you maintain a site running phpBB forums load this patch immediately. Apparently the exploit allows the hacker to gain root access to mySql. Many sites have been hacked including phpBB’s own support forum. Ouch.

I haven’t been able to find much info on how the exploit works. The code change in this patch seems trivial and I still don’t understand how it fixes the problem with the forums. If anyone has more insight I would love to hear.

Supposedly this is only a temporary patch and we need to stay tuned for a permanant fix.

Full discussion on the security flaw including input from ‘jessbunny’, the user that reported the problem and then proceded to use the exploit against phpBB.com


Share it:
These icons link to social bookmarking sites where readers can share and discover new web pages.

  • Digg
  • del.icio.us
  • DZone
  • Ma.gnolia
  • Netscape
  • Reddit
  • StumbleUpon
  • YahooMyWeb