سلام خدمت دوستان گلم
باگ جدیدی که در دو پلاگین پر استفاده ویبولتین استفاده میشود را به شما دوستان به زودی معرفی خواهم کرد
این پلاگین : Cyb - Login To User Account
این پلاگین که توانایی لوگین شدن ادمین با یوزر کاربر بدون استفاده از پسورد را میدهد دارای باگ خطر ناکی هست که نفوذ گران و هکر ها میتوانند به راحتی از این طریق به یوزر های سایت دسترسی بگیرند نوع نفوذ و استفاده عمل hijack میباشد
کد PHP:
* Quarantine Notification *
The following modification has had an exploit reported in it, and has been 'quarantined' by vBulletin.org.
The author of the modification has been informed and asked to provide a fix, until this fix is provided the modification will remain in the vbulletin.org graveyard.
The discovered vulnerability is classified as severe and you should take action ASAP.
If you are currently using this modification then you are advised to uninstall it.
If the modification consists of a product then disabling the product should be all that is required. Do not uninstall the product as this may delete any data associated with it. If the modification also included new files then you should remove (or rename) them.
Once the author has uploaded a fix you will be notified that it has been restored.
علاقه مندی ها (Bookmarks)