The Arcive of vBulletin Modifications Site. |
|
Safe or not ?? Details »»
|
|||||||||||||||||||||||||
Hi,
I was searching around for games for my arcade and stumbled upon a post suggesting this mod is subject to a SQLi error and it is one of the most exploited SQLi's ever oO !!! So is this true ? If so is there an exploit fix ? The post saying this was posted on 05-18-2013 and the last update for this mod was on 27 Feb 2012 so im a bit worried now .... Show Your Support
|
|||||||||||||||||||||||||
| Comments |
|
#2
|
|||
|
|||
|
I checked the source quickly (mainly the queries), but it seems safe.
addslashes is used at some places which is not safe if you use a certain character encoding, but I doubt anyone would ever use any of these character encodings for a vBulletin forum. |
|
#3
|
|||
|
|||
|
I just sent you a pm of the warning post I found...
|
|
#4
|
|||
|
|||
|
Please send me a copy of the post or the URL, I would appreciate it.
|
|
#5
|
|||
|
|||
|
Quote:
--------------- Added [DATE]1409690013[/DATE] at [TIME]1409690013[/TIME] --------------- So whats the verdict ? --------------- Added [DATE]1409691313[/DATE] at [TIME]1409691313[/TIME] --------------- im trying to reply to your PM but this site keeps timing out ? |
|
#6
|
|||
|
|||
|
[quote=fookaa;2513538]Sent..
--------------- Added 02 Sep 2014 at 13:33 --------------- So whats the verdict ? Taking a quick look at version 2.7.2+, this should not be an issue, as they are now parsing the query string for SQL commands among other things. You should be using a PHP version of 3.5 or greater as a minimum. I will do some tests on it later this evening.
|
| 2 благодарности(ей) от: | ||
| blind-eddie, fookaa | ||
|
#7
|
||||
|
||||
|
What do you think about letting vBulletin Input Clean handle it ??
|
|
#8
|
|||
|
|||
|
Any news on this ?
|
|
#9
|
|||
|
|||
|
It's safe.
|
|
#10
|
||||
|
||||
|
Definitely safe.
|
![]() |
|
|