vBadvanced Forums  
Go Back   vBadvanced Forums > vBadvanced.com > Announcements

Reply
 
Thread Tools Display Modes
  #1  
Old 01-26-2012, 03:18 PM
Brian's Avatar
Brian Brian is offline
Administrator
 
Join Date: Jan 2004
Location: Georgia, USA
Posts: 34,240
Default vBa CMPS Security Flaw Discovered

Earlier today we were informed of a security flaw in all versions of vBadvanced CMPS which could potentially allow a hacker to run a remote file on a server with vBa CMPS. Fortunately this exploit requires that PHP on your server to have been configured with "register_globals" enabled, and most hosting companies will not enable this since it is widely known to cause security issues. Regardless, we highly recommend that all customers upgrade to the versions of vBa CMPS that have just been released in the Members' Area here (v3.2.3 for vB3, or v4.1.3 for vB4) as soon as possible to prevent any potential damage resulting from the flaw being exploited.
__________________
Frequently Asked Questions
CMPS Users Manual

For vBadvanced software assistance, please use the support forums.
Unsolicted PMs, IMs, and email will not be responded to.
If you have a non-software related question or problem with your account, please submit a support ticket.

Last edited by Brian; 01-28-2012 at 10:56 AM.
Reply With Quote
  #2  
Old 01-26-2012, 04:15 PM
attroll's Avatar
attroll attroll is offline
Senior Member
 
Join Date: Jan 2004
Posts: 818
Default

I have installed this and when I go to run the update it tell me
"You are already running the current version of vBadvanced CMPS!"
Reply With Quote
  #3  
Old 01-26-2012, 04:51 PM
slipkot slipkot is offline
Junior Member
 
Join Date: Mar 2008
Posts: 3
Default

Same problem with attroll...
Reply With Quote
  #4  
Old 01-26-2012, 06:06 PM
Brian's Avatar
Brian Brian is offline
Administrator
 
Join Date: Jan 2004
Location: Georgia, USA
Posts: 34,240
Default

Sorry about that. I was in such a hurry to get the new versions out that I completely forgot to update the version number in the install file. There were no changes to the database so it's not actually necessary to run the upgrade option from the vbacmps_install.php file since all it would really do is update your version number. As long as you uploaded the new files then you're patched.
The install files in the download packages have been corrected now though.
__________________
Frequently Asked Questions
CMPS Users Manual

For vBadvanced software assistance, please use the support forums.
Unsolicted PMs, IMs, and email will not be responded to.
If you have a non-software related question or problem with your account, please submit a support ticket.
Reply With Quote
  #5  
Old 01-26-2012, 09:53 PM
thecore762 thecore762 is offline
Member
 
Join Date: Jul 2008
Posts: 73
Default

Brian, after uploading the files the front page doesn't work.
See www.47r-squad.com

Nothing appears, not sure whats going on.

I had to revert the files back to 4.1.2 since 4.1.3 was not displaying the front page.

Last edited by thecore762; 01-26-2012 at 09:58 PM.
Reply With Quote
  #6  
Old 01-26-2012, 11:00 PM
Deimos Deimos is offline
Junior Member
 
Join Date: Mar 2004
Posts: 4
Default

Same problem here, a blank white page when the new files are uploaded and upgrade run
Reply With Quote
  #7  
Old 01-26-2012, 11:08 PM
thecore762 thecore762 is offline
Member
 
Join Date: Jul 2008
Posts: 73
Default

Quote:
Originally Posted by Deimos View Post
Same problem here, a blank white page when the new files are uploaded and upgrade run
At least we know it's just not just me.
Reply With Quote
  #8  
Old 01-27-2012, 12:01 AM
Grae Grae is offline
Junior Member
 
Join Date: Mar 2005
Posts: 28
Default

Quote:
Originally Posted by Deimos View Post
Same problem here, a blank white page when the new files are uploaded and upgrade run
I'm having the same problem.
3.2.3
Reply With Quote
  #9  
Old 01-27-2012, 12:32 AM
whitey10tc whitey10tc is offline
Junior Member
 
Join Date: May 2011
Posts: 1
Default

Yup same issue, blank white page after upgrade. Guess it's better than having a security issue.
Reply With Quote
  #10  
Old 01-27-2012, 01:12 AM
attroll's Avatar
attroll attroll is offline
Senior Member
 
Join Date: Jan 2004
Posts: 818
Default

I had the blank front page at first too. I re-uploaded the files a couple of times and refreshed the screen and then it started working. Don't know why but it did.
Reply With Quote
  #11  
Old 01-27-2012, 01:22 AM
thecore762 thecore762 is offline
Member
 
Join Date: Jul 2008
Posts: 73
Default

Quote:
Originally Posted by attroll View Post
I had the blank front page at first too. I re-uploaded the files a couple of times and refreshed the screen and then it started working. Don't know why but it did.
I tried few times but 0 success.
Reply With Quote
  #12  
Old 01-27-2012, 01:59 AM
attroll's Avatar
attroll attroll is offline
Senior Member
 
Join Date: Jan 2004
Posts: 818
Default

You may want to check your cmps_index.php file. Did you overwrite it with the new one and forget to make the proper changes.
Reply With Quote
  #13  
Old 01-27-2012, 02:17 AM
thecore762 thecore762 is offline
Member
 
Join Date: Jul 2008
Posts: 73
Default

I overwrited and made sure it was.
Reply With Quote
  #14  
Old 01-27-2012, 09:09 PM
Mikea113n Mikea113n is offline
Junior Member
 
Join Date: Feb 2011
Posts: 14
Default

This is a known issue that code cause. new one has been released for the fix. re download and reinstall. It will fix it. I was freaking out as well.
Reply With Quote
  #15  
Old 01-31-2012, 03:26 PM
Black Tiger Black Tiger is offline
Senior Member
 
Join Date: Sep 2006
Posts: 118
Default

The new 3.2.3 release is missing the ecdownloads and/or downloads2 modules.
Reply With Quote
  #16  
Old 02-01-2012, 12:37 AM
CareyCrew CareyCrew is offline
Gone. vB is worthless now
 
Join Date: Sep 2007
Posts: 1,676
Default

Quote:
Originally Posted by Black Tiger View Post
The new 3.2.3 release is missing the ecdownloads and/or downloads2 modules.
No such module was ever produced by Brian, those are 3rd party additions.
Reply With Quote
  #17  
Old 02-01-2012, 05:38 PM
Artes_Marciales Artes_Marciales is offline
Junior Member
 
Join Date: Jun 2007
Posts: 15
Default

I uploaded all the files but...
Powered by vBadvanced CMPS v3.2.2

Is this normal?
Reply With Quote
  #18  
Old 02-02-2012, 12:33 AM
A.Chakery A.Chakery is offline
Junior Member
 
Join Date: Nov 2010
Posts: 24
Default

Quote:
Originally Posted by Artes_Marciales View Post
I uploaded all the files but...
Powered by vBadvanced CMPS v3.2.2

Is this normal?
yes it is.

You should run the upgrade process if you wanna have the new version in your products system.
Reply With Quote
  #19  
Old 02-02-2012, 12:34 AM
A.Chakery A.Chakery is offline
Junior Member
 
Join Date: Nov 2010
Posts: 24
Default

Brian is it ok to use the old news.php ? cause I did so much customizations to it and at the moment I have not enough time to do the custom codding again.

thanks
Reply With Quote
  #20  
Old 02-02-2012, 02:40 AM
Artes_Marciales Artes_Marciales is offline
Junior Member
 
Join Date: Jun 2007
Posts: 15
Default

Quote:
Originally Posted by A.Chakery View Post
yes it is.

You should run the upgrade process if you wanna have the new version in your products system.
OK, thanks.
I understand that it is not necessary to run the installer right?
Reply With Quote
Reply

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Security Flaw - can it be fixed without a full upgrade? PhilMcKrackon "How Do I..." Questions 2 11-05-2012 05:35 AM
Security Flaw - How to fix without upgrading? BirdOPrey5 "How Do I..." Questions 3 11-02-2011 10:00 AM
vBa Links Security Flaw & New Releases Brian Announcements 2 11-01-2011 06:45 AM
Various Bugs Discovered John Bugs & Issues From v2.0.0 2 07-26-2010 03:12 PM
vBa CMPS Security Alert! 3.2.2 & 4.0 RC1 Released Brian Announcements 22 03-15-2010 03:48 AM


All times are GMT -4. The time now is 03:16 PM.

Forums Powered by vBulletin, Copyright ©2000-2009, Jelsoft Enterprises Ltd.
Please note that vBadvanced is in no way affiliated with Jelsoft Enterprises Ltd, nor will Jelsoft be able to provide any support for our products.