
01-07-2004, 09:18 AM
|
 |
|
|
Join Date: Jan 2002
Posts: 7,604
Благодарил(а): 0 раз(а)
Поблагодарили:
0 раз(а) в 0 сообщениях
|
|
If you see this error email:
Quote:
Database error in vBulletin 2.3.2:
Invalid SQL: SELECT allowsmilies,public,userid,eventdate,event,subject FROM calendar_events WHERE eventid = 14 union (SELECT allowsmilies,public,userid,'0000-0-0',version(),userid FROM calendar_events WHERE eventid = 14)
mysql error: You have an error in your SQL syntax near 'union (SELECT allowsmilies,public,userid,'0000-0-0',version(),userid FROM calend' at line 1
mysql error number: 1064
Date: Tuesday 06th of January 2004 11:09:36 PM
Script: http://forums.*****.com/calendar.php?s=&action=edit&eventid=14%20union%20( SELECT%20allowsmilies,public ,userid,\'0000-0-0\',version(),userid%20FROM%20calendar_events%20WH ERE%20eventid%20=%2014)
Referer:
|
That is someone trying (and failing) to take advantage of the security error in vB 2.3.x.
Taken from:
http://www.vbulletin.com/forum/showthread.php?t=91408
So upgrade your 2.3.3 forums.  Go to vB3.
Added - the security issue only affects calendar.php APPARENTLY.
So just upload a new calendar.php found here:
http://www.vbulletin.com/forum/showp...33&postcount=3
|