possible security issue possible security issue
 

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Main Menu

possible security issue

Started by Beekeeper, November 24, 2011, 12:20:52 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Beekeeper

I upgraded to cpg1.5 a couple of weeks ago
Other than myself as Admin there is one registered user who is known to me.
This evening I received this email

This email was sent at 2011-11-23 21:50:38 using the contact form at http://www.mareham-le-fen.co.uk/photo/contact.php from the IP address 109.73.68.18

The guest named «tpyrnpovod» with the email address hdrjdw@hnkvzi.com said:
bVimgc <a href="http://pfbajozeyuzq.com/">pfbajozeyuzq</a>, ialmlcbkdgqd, [link=http://xhwcofrgeosf.com/]xhwcofrgeosf[/link], http://avofsuwezjef.com/

obviously contact.php isn't visible on the webpage so the person must know the that there is a contact.php file in coppermine, Is this something I should worry about or is it just someone trying to prove how clever they are

Αndré

Quote from: Beekeeper on November 24, 2011, 12:20:52 AM
obviously contact.php isn't visible on the webpage
Just have a look at Home > Contact ::)

Beekeeper

Thanks for that,
For some reason I have never noticed the contact option on the home link, it was the message content that made me assume it could be a possible attack attempt of some discription,
My appologies for wasting your time

Αndré

You can disable the contact form in the config, if you don't need it.


Additionally, please
Quote from: Joachim Müller on September 28, 2008, 12:46:26 PM
tag your answer as "solved" by clicking on the "Topic Solved" button on the bar at the left hand side at the bottom of your thread.