Joeychgo
09-01-2006, 03:32 PM
Today, we have had several support tickets in regards to defaced vBulletin forums. Upon investigation of the weblogs, we've determined that a vulnerability exists in FlashChat v4.5.7 (at least) that...
More... (http://www.vbulletin.com/forum/showthread.php?t=198902&goto=newpost)
Paul M
09-01-2006, 04:59 PM
The bit about securityfocus is a red herring, they seem to have confused Tufat Flashchat with another product (also called Flashchat). However, in the last couple of days an exploit was found in Tufat's Flashchat, involving the aedating CMS (http://forum.tufat.com/showthread.php?t=24428) file.
The simple way to avoid this for anyone with vbulletin running integrated with Flashchat is to delete all the files in Flashchats CMS folder except the vbulletin##CMS.php file that they are using (## = 30, 35 or 36) - all the other files are for other systems, and not used.
Thanks Paul. I was just about to post the link to .org. :)
Joeychgo
09-01-2006, 05:45 PM
Thanks for keeping us up to date Paul