Advanced search  

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Pages: [1]   Go Down

Author Topic: SQL Injection bug  (Read 2761 times)

0 Members and 1 Guest are viewing this topic.

evilpandas

  • Coppermine newbie
  • Offline Offline
  • Posts: 2
SQL Injection bug
« on: February 23, 2009, 11:34:25 pm »

Ok, so i'd been running an unpatched old version of coppermine for a while. I was ignorant by the bugs out there.

My site both Wordpress and Coppermin have been infected by the SQL Injection bug or so I believe.
http://www.google.co.uk/search?hl=en&client=firefox-a&rls=org.mozilla%3Aen-GB%3Aofficial&q=site%3Awww.evilpandas.co.uk&btnG=Search&meta=

There are no comments allowed in my gallery. But it seems as though my google results have been hijacked.

I've upgraded to the latest version of Coppermine, added the modpack, but i'm stuck.

What do i do next? Do I just wait for google to re-index my site?

Thanks in advance
Logged

François Keller

  • Dev Team member
  • Coppermine addict
  • ****
  • Country: fr
  • Offline Offline
  • Gender: Male
  • Posts: 9094
  • aka Frantz
    • Ma galerie
Re: SQL Injection bug
« Reply #1 on: February 24, 2009, 07:19:48 am »

and what is the link to your gallery ?
Did you clean up your Albums folder from unexpected files ?
Logged
Avez vous lu la DOC ? la FAQ ? et cherché sur le forum avant de poster ?
Did you read the DOC ? the FAQ ? and search the board before posting ?
Mon Blog

evilpandas

  • Coppermine newbie
  • Offline Offline
  • Posts: 2
Re: SQL Injection bug
« Reply #2 on: February 24, 2009, 08:50:43 am »

Apologies.

http://www.evilpandas.co.uk/Gallery is the address.
I have removed the unexpected files, looked through throroughly for hours.
Logged

Abbas Ali

  • Administrator
  • Coppermine addict
  • *****
  • Country: in
  • Offline Offline
  • Gender: Male
  • Posts: 2165
  • Spread the PHP Web
    • Ranium Systems
Re: SQL Injection bug
« Reply #3 on: February 24, 2009, 09:00:54 am »

Make sure you have followed this thread.
Logged
Chief Geek at Ranium Systems

Joachim Müller

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 47843
  • aka "GauGau"
    • gaugau.de
Re: SQL Injection bug
« Reply #4 on: February 25, 2009, 09:40:47 am »

Not related to initial install, moving accordingly.
Logged
Pages: [1]   Go Up
 

Page created in 0.02 seconds with 20 queries.