Running 7.7 and got tons of these spam/hack emails from my board today. Not sure if there is a hole, but found it not good they are trying to execute SQL here:
Quote:
Database error in vBulletin 3.8.7:
Invalid SQL:
SELECT * FROM post_thanks AS post_thanks INNER JOIN user AS user USING (userid) WHERE post_thanks.postid IN () ORDER BY post_thanks.username ASC;
MySQL Error : You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ') ORDER BY post_thanks.username ASC' at line 1
Error Number : 1064
Request Date : Friday, January 13th 2012 @ 11:35:36 AM
Error Date : Friday, January 13th 2012 @ 11:35:36 AM
Script : /forums/post_thanks.php?do=post_thanks_remove_user&=%27 %20UNION%20ALL%20SELECT%20NULL%2C%20NULL%2C%20NULL--%20%20AND%20%27uqdT%27%3D%27uqdT
Referrer :
IP Address : 95.140.125.10
Username : Unregistered
Classname : vB_Database
MySQL Version :
|
Any thoughts?