 |
|
|
PHP Bug Allows Password Theft
Last
Updated:
November 30, -0001
A new security hole in PHP allows users to steal database passwords from phpBB bulletin board software installations.
According to Netcraft an attacker can exploit the PHP flaw to retrieve the uername and password of a PHP applications MySQL database.
The phpBB team has already notified users of the vulnerability and urges users and hosting providers to upgrade.
PHP.net has fixed versions 4.3.10 and 5.03 of the software.
Web Hosting providers are urged to upgrade to either of the above versions.
Web Hosting providers which utilize cPanel should consider 4.3.10 as a stable upgrade, and once 4.3.10 has been setup re-install zend optimizer as the old version will NOT work with php 4.3.10
|
|
 |
|