English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Critical vulnerability found in phpBB software

Roel
Kaspersky Lab Expert
Posted February 28, 20:19  GMT
Tags: Website Hacks, Santy, PHP
0
 

phpBB.com have announced that their phpBB software contains a critical vulnerability.
This news comes just days after the release of 2.0.12, which was released to adress certain other vulnerabilities.

Exploitation of this vulnerability gives administrative rights, meaning arbitrary code can be executed.

This could mean that we see a Santy-like scenario all over again, with a lot of servers being affected.
Although I believe we would see only a few defaced websites in this case, instead I'm expecting a lot of zombies.

phpBB.com have released version 2.0.13 which is no longer vulnerable for this vulnerability.

You are severely urged to update to the latest version as soon as possible.


Comments

If you would like to comment on this article you must first
login


Bookmark and Share
Share

Analysis

Blog

Alerts