Mihalism Multi Forum Host 3.0.x Remote File Inclusion Vulnerability
Sunday, December 30th, 2007If you are running a version of Mihalism Multi Forum Host that was downloaded prior to December 30, 2007, then please download it again, and reupload the following files to fix a potential security risk within the forum loader.
- source/includes/load_forum.php
The security risk would allow for a hacker to modify the root path that Mihalism Multi Forum Host uses and include a file that could potentially damage your site and server. If your PHP version is configured to disable the register_globals setting, then there is nothing to worry about, but it is still highly recommended to reupload.
To check if the register_globals setting is disabled on your server, download and upload to your server the attached file. Once uploaded, open the file in your web browser, and it will let you know if your server is secure. Don’t forget to delete the file once you have used it.
register_globals Checker: rg_check.php (Hypertext Preprocessor File)
If your site has been hacked:
If your website has been hacked due to this vulnerability, then contact a Mihalism staff member and we will provide for free a clean up for your site. This clean up will repair any damaged files and delete any weird files the hackers may have left behind.