Author Topic: Being forced to update by my host, how to do it...  (Read 3528 times)

0 Members and 1 Guest are viewing this topic.

Offline djith

  • Jr. Member
  • **
  • Posts: 73
    • View Profile
Being forced to update by my host, how to do it...
« on: March 15, 2007, 06:22:22 PM »
I received this e-mail from lunarpages, my host, and it says that i need to update from 4images 1.7.1 to 1.7.4 urgently due vulnerable script!

Dear Customer,

Our server scanner has detected a vulnerable script on your account
which may require updating.
Please see http://www.lunarforums.com/forum/index.php?topic=39202.0 for
further information, this notice is for information only.

If the script is not updated within the next 48 hours a subsequent scan
will disable it as insecure scripts can lead to compromised accounts.
Thank you in advance for your patience and understanding with regards
to this.
The following are the scripts:

Script: /home/*****/*****l/config.php
Description: Vulnerable 4images gallery (update to 1.7.4 required)


If you require any further information or help with regards to this,
please contact support.
Kind Regards,

Lunarpages Support
_________________________________________________________________

So do i only need to update the config.php ?
I've seen there is no config.php in 1.7.4

What to do now? how to solve and fix this?

would be glad for any advice,

Mathew

Offline CeJay

  • Sr. Member
  • ****
  • Posts: 425
    • View Profile
Re: Being forced to update by my host, how to do it...
« Reply #1 on: March 15, 2007, 10:57:17 PM »
try....http://www.4homepages.de/forum/index.php?topic=15187.0


if you have mods you can use something like winmerge

manurom

  • Guest
Re: Being forced to update by my host, how to do it...
« Reply #2 on: March 16, 2007, 12:14:15 AM »
Hello;
the explanation is here: http://secunia.com/advisories/22349/
You run the version 1.7.1.
Upgrade to 1.7.4 or apply this patch: [1.7 - 1.7.3] Security fix for SQL injection in global.php