Pixelpost

Authentic Photoblog Flavour


Go Back   Pixelpost Forum > SUPPORT / INFORMATION > Pixelpost Help

Post Reply
 
Thread Tools
  #1  
Old 01-16-2008, 03:09 PM
solar-flare's Avatar
solar-flare Offline
forum loafer
 
Join Date: May 2005
Location: Baltimore, MD
Posts: 2
Send a message via AIM to solar-flare Send a message via MSN to solar-flare
Exclamation Security Warning: SQL Injection

FYI guys, a SQL injection exploit has been found in version 1.7. It's listed on milw0rm.

http://www.milw0rm.com/exploits/4924
__________________
www.solar-flare.us

Hosted by Pseudo-Servers Hosting:
www.pseudo-servers.com
Reply With Quote
  #2  
Old 01-16-2008, 06:04 PM
Dennis's Avatar
Dennis+ Offline
Team Pixelpost
 
Join Date: Jul 2006
Posts: 2,600
Send a message via MSN to Dennis
Thanks for mentioning, we're on it right now.
__________________
My photoblog, powered by PixelPost 1.9 dev SVN | My Pixelpost Addons | My Cool Photoblog profile
Reply With Quote
  #3  
Old 01-16-2008, 07:57 PM
jaywilliams's Avatar
jaywilliams+ Offline
Team Pixelpost
 
Join Date: Sep 2005
Posts: 1,059
Send a message via AIM to jaywilliams Send a message via MSN to jaywilliams Send a message via Yahoo to jaywilliams Send a message via Skype™ to jaywilliams
We've fixed the bug, and will be releasing a new version of Pixelpost later today that has the patch.

UPDATE:
The new version has ben released, it can be downloaded here:
http://www.pixelpost.org/
__________________
Jay Williams | A Different View

Last edited by jaywilliams; 01-16-2008 at 09:35 PM.
Reply With Quote
  #4  
Old 01-16-2008, 09:54 PM
guiz Offline
pp veteran
 
Join Date: Oct 2006
Location: Italy
Posts: 92
I have 1.7 installed.
can I simply copy the new files over the 1.7 dir or must I upgrade? I think the 1.
Reply With Quote
  #5  
Old 01-16-2008, 10:28 PM
Dkozikowski's Avatar
Dkozikowski+ Offline
Team Pixelpost
 
Join Date: Oct 2005
Posts: 1,865
Send a message via AIM to Dkozikowski
Download Pixelpost v1.7.1

And follow the standard upgrade procedure as outlined here.
Reply With Quote
  #6  
Old 01-16-2008, 11:06 PM
dhdesign's Avatar
dhdesign Offline
pixelpost guru
 
Join Date: Mar 2007
Location: Ohio
Posts: 433
Does this mysql injection issue affect PP version 1.6? I haven't upgraded to 1.7 yet, but there is a warning flashing on my Options page in the admin section that I need to upgrade immediately.
__________________
My photoblog: KP Images
Reply With Quote
  #7  
Old 01-16-2008, 11:52 PM
Dkozikowski's Avatar
Dkozikowski+ Offline
Team Pixelpost
 
Join Date: Oct 2005
Posts: 1,865
Send a message via AIM to Dkozikowski
It's possible that this issue has been around since or before v1.6.

I would not take the chance and upgrade to v1.7.1 as soon as possible!
Reply With Quote
  #8  
Old 01-17-2008, 01:22 AM
dhdesign's Avatar
dhdesign Offline
pixelpost guru
 
Join Date: Mar 2007
Location: Ohio
Posts: 433
Thanks - just finished the upgrade, and so far, everything is working okay.
__________________
My photoblog: KP Images
Reply With Quote
Post Reply


Thread Tools




All times are GMT. The time now is 02:13 PM.

Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd. | Style Design: d3 designs