nBill Community nBill Home Page
03/September/2010, 12:36:54 AM *
Welcome, Guest. Please login or register.

Login with username, password and session length
News: Click Here for the nBill home page, or take a tour.  
 
   Home   Help Search Login Register  
Pages: [1]
  Print  
Author Topic: IMPORTANT SECURITY ANNOUNCEMENT  (Read 2677 times)
netshine
Administrator
Hero Member
*****
Offline Offline

Posts: 3,460


View Profile
« on: 27/June/2008, 08:01:01 AM »

Please Note: Since the release of nBill 1.2.1, this patch is no longer required. All users are encouraged to upgrade to nBill 1.2.1.

It has come to our attention that a security vulnerability exists in nBill version 1.2.0 SP1. A patch file is attached to this post - all users are urged to apply it immediately. Just replace your /components/com_netinvoice/netinvoice.php file with the attached (also available here if you cannot see the attachment below - unzip first!).

A number of people have reported attempted SQL injection attacks, which in virtually every case will have failed, but after some investigation it has been found that a vulnerability does exist if the hacker has knowledge of or can guess the contents of an encrypted file. The sample code provided in a recent secunia advisory was ineffective and would not result in a successful attack - as far as we are aware, nobody has yet been compromised. Even so, it is advisable to ensure that you change your Joomla administrator password after applying this patch.

If you are running an earlier version of nBill, it is recommended that you upgrade to 1.2.0 SP1 and apply the patch.

[attachment deleted by admin]
« Last Edit: 08/July/2008, 03:08:45 PM by netshine » Logged
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS!