February 10, 2012, 17:07:33 *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Add your links to our directory. Click here to add your links.
 
  Home   Forum   Help Search Directory Calendar Login Register    RSS 2.0 feedAtom feed


News
Add your links to our directory. Click here to add your links.
Pages: [1]
  Print  
Author Topic:

IMPORTANT: SEO4SMF Multiple Vulnerabilites

 (Read 2460 times)
0 Members and 1 Guest are viewing this topic.
h4xgrrl
Newbie
*

Points: 0
Offline Offline

Posts: 1


« on: January 27, 2009, 12:41:36 »

I highly suggest that you do not use SEO4SMF, the newest version or otherwise! It is not updated regularly and there are several recent and outstanding vulnerabilities that can lead to your site getting hacked!

I found out about them from the following sites:
Code:
http://www.milw0rm.com/exploits/7723

(google translated from Spanish) http://translate.google.com/translate?prev=_t&hl=en&ie=UTF-8&u=http%3A%2F%2Fforo.elhacker.net%2Fbugs_y_exploits%2Ffalla_en_el_mod_seo4smf_para_smf-t241029.0.html&sl=es&tl=en&history_state0=

(original topic in Spanish) http://foro.elhacker.net/bugs_y_exploits/falla_en_el_mod_seo4smf_para_smf-t241029.0.html

The person who found this exploit patched their own forums (as stated in their post), but obviously only wants to provide the vulnerabilities so that hackers may exploit other SMF forums using SEO4SMF.

I HIGHLY RECOMMEND that you uninstall SEO4SMF until someone patches this and makes the patch publicly available.

This finding is recent, as of January 9th, 2009!



Note: I do not claim to be a PHP/MySQL developer or expert, so I cannot offer any support. However I do read Spanish, so...this is just my personal warning.
Logged


rostam
Jr. Member
**

Points: 0
Offline Offline

Posts: 12


« Reply #1 on: January 27, 2009, 14:05:36 »

Did you read this?

http://www.webmasterstalks.com/seo-4-smf/seo4smf-2-9-10-t1700.0.html

This has already been fixed in the newest (0.2.9.10) version.
Logged
xulescu
Administrator
Sr. Member
*****

Points: 8
Offline Offline

Posts: 257


WWW
« Reply #2 on: August 09, 2009, 14:08:38 »

Thanks for pointing this out !
Logged

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
TinyPortal v0.9.7 © Bloc
Valid XHTML 1.0! Valid CSS!