A recent vBulletin vulnerability puts Web administrators at risk
The
BBC has learned a major vBulletin software flaw that gives users the
ability to view and access passwords administrators use to maintain
the site. Specifically, security experts warn the vulnerability can
lead to SQL username, SQL server, SQL password and SQL port
information
VBuletin is used today for many of the
internet forums and online discussion boards people sign up and share
information on. The new 3.8.6 of the forum software was released on
July 13 and can be exploited even by regular PC users, the BBC
learned.
"It is very worrying that they are releasing a
product which has such
a horrendous flaw," said Stuart Wright, AV Forums head, in
an interview with BBC.
"I'm really not happy - we rely on this software for our
business."
AV Forums has more than 300,000 members, but
is not using the vBulletin version in question. However, Internet
Brands, which develops and markets vBulletin, has informed domain
owners and has told them a patch is available to fix the problem.
A
vBulletin patch was promised, but it's unknown how many
administrators have successfully used it.
"There's no chance that the iPhone is going to get any significant market share. No chance." -- Microsoft CEO Steve Ballmer
|
Latest By Michael Barkoviak
Most Popular ArticlesReport: Apple to Debut iPad 3 During First Week of March February 10, 2012, 9:36 AM Nikon Announces 36.3MP D800, D800E D-SLRs February 7, 2012, 10:11 AM Quick Note: Acura Unveils Production Version of ILX Hybrid Sedan February 8, 2012, 9:10 AM Google's Motorola Mobility Purchase Approval Expected Next Week February 9, 2012, 3:02 PM China Prepares to Fine Apple, Possibly Ban iPad for Trademark Abuse February 7, 2012, 12:09 PM
|