Home » General » sticky Security Release - NinkoBB 1.3RC5 (4 Posts)

5 months ago #344
pic Nijikokun
Plugin mastah - 153 posts
I should probably update this security flaw too! - Aldarn

--------------------------------------------------------------------------------------------------------------------------------

Please update your files or if you don't want to risk all of the files just `admin.php` exploit was found here:
http://packetstormsecurity.org/filedesc/ninkobb-addadmin.txt.html

I have fixed the exploit and yes it did work. I tested it on my own copy of it. I forgot to exit or kill the PHP process and forms ignore headers. Human error. Well, its fixed in RC5 and this was a very quick release with no fixes other than that one as I found out about it about 10 minutes ago.

Downloads can be found here.
5 months ago #346
pic noodles101
Member - 6 posts
Also works in v1.2x just had my site hit with it...
5 months ago #348
pic Nijikokun
Plugin mastah - 153 posts
Its a simple fix
1 month ago #444
pic Mosad
Member - 1 posts
Nice to hear that.
4 weeks ago #466
pic 7mOOdi
Member - 3 posts
Nice to hear that.