[caption id="attachment_676" align="aligncenter" width="408"]
SQL injection vulnerability[/caption] An administrator of a hacker community forum, Nytro found sql injection vulnerability in Vbulletin forum. Nytro has now confirmed on his Romanian Security team forum that patches are released for the flaw which was found on Monday.
Emergency patches released for SQL injection vulnerability
The technical support leader of Vbulletin Wayne Luke said that the flaw found could allow the attackers to make a sql injection attack. This would give an access to the malicious attacker to run and execute sql commands. To resolve this sql vulnerability, Vbulletin forum developers have released patches for 5.0.4, 5.0.5, 5.1.0, 5.1.1 and 5.1.2 versions of Vbulletin. The users would need to manually apply the code and fix the bug.
What is Vbulletin?
Vbulletin provides online cloud base service and allows you to build forums. Vbulletin 5 connects and cloud hosting services are the two popular products offered. It is written in PHP and my SQL databases. The company build's commercial online forum software. Companies such as Electronic Arts, Sony pictures, NASA Valve Corporation and Zynga run on Vbulletin.Vbulletin official website link[caption id="attachment_677" align="aligncenter" width="614"]
SQL injection vulnerability found in Vbulletin hosted websites[/caption]
Earlier attack on Vbulletin hosted websites
This is not the first time that attackers have attacked Vbulletin based websites. Last year also hackers stole around 1 million user email ids and passwords from UbuntuForums.org. openSUSE Linux forum was also hacked 2 years ago with the same SQL injection method. Among all, the official forum of Vbulletin was vulnerable last year.
You might also be interested to read
[caption id="attachment_490" align="alignleft" width="150"]
Certified web application security expert[/caption] [caption id="attachment_435" align="alignleft" width="150"]
DNS Sinkhole prevent against malware attack[/caption]