phpBB Private Message Vulnerability fix


Del.icio.us  Digg  Google  Spurl  Blink  Furl  Y! MyWeb  
Share:
Sponsors:


The bug can allow attackers to obtain password hashes, all existing users of phpBB 2.0.x make the change specified below, it is highly recommended.

To fix this flaw please open modules/Private_Messages/index.php in any text editor and follow the following instruction posted.... Find:
$pm_sql_user .= "AND ( ( pm.privmsgs_to_userid = " . $userdata['user_id'] . "

Replace with:
$pm_sql_user = "AND ( ( pm.privmsgs_to_userid = " . $userdata['user_id'] . "

The difference between the two lines is the deleted dot after $pm_sql_user.

Article submitted by: Telli
Last Update: 03-29-2004
Category: News

Print | E-mail


Current rating: 5 by 26 users
Would you recommend this article to a friend?

Not a Chance 12345678910 Absolutely

Please register or sign-in to post comments.


Related News Stories

(15,806 reads) 12-02-2007
 · Don't Fall for Jury Duty Scam
(13,712 reads) 07-20-2007
 · 500MB Free hosting [No-Ads No-Spamming]
(31,036 reads) 12-24-2006
 · phpBB 2.0.22 and BBtoNuke 2.0.22 released
(15,716 reads) 08-05-2006
 · Vista hacked at Black Hat.
(13,070 reads) 08-04-2006
 · Dozen Windows, Office updates coming next week.
(13,518 reads) 07-19-2006
 · Microsoft Lawsuits Help Protect Consumers.
(13,283 reads) 07-18-2006
 · Symantec sees an Achilles' heel in Vista.