Please! Check your modules/Reviews/index.php file for the following code. There should be 2 instances.
WHERE id=$id
If you have it, then you MUST modify it to
WHERE id='$id' .
Otherwise your admin passwords can be exposed. They are still encrypted, but depending on how serious someone was to get them, they might! please note that Chatserv's Patches have this fix in them, but FB should have patched his releases by now and hasn't!
Admin Note: See this post for further discussion and code for protecting your site.
SQL Injection Vulnerability!
Posted on Wednesday, February 04, 2004 @ 20:05:04 CST in Security
|
PHP-Nuke Patched 2.1
Posted on Wednesday, February 04, 2004 @ 14:29:39 CST in Security
|
MSN looking fraud
Posted on Thursday, January 15, 2004 @ 10:05:40 CST in Security takaharu writes:
|
PHP-Nuke Patched R.C. 2
Posted on Friday, December 05, 2003 @ 08:29:36 CST in Security chatserv writes:
|
And yet another admin.php security hole!
Posted on Tuesday, October 14, 2003 @ 21:27:30 CDT in Security
|
PHP-Nuke admin.php security hole fix!
Posted on Tuesday, October 14, 2003 @ 13:20:34 CDT in Security
|