Invision Community 4: SEO, prepare for v5 and dormant account notifications Matt November 11, 2024Nov 11
Posted July 27, 201311 yr There's an exploit in 3.4.5, I don't know what it is. All I know is that my MySQL database has been leaked and my website has been defaced twice now. I don't know where to post this or how to get it across but yeah. Spent $200 on the license and I can't even use it.
July 27, 201311 yr You better submit a ticket. No one can do nothing here for you. If really there's an exploit, they'll release a patch.
July 27, 201311 yr It could be a security vulnerability in your server configuration, IPB recently released a patch about a server configuration error. It might not actually be IPS's software.
July 27, 201311 yr You can easily submit a ticket by going here, https://www.invisionpower.com/clients/index.php?app=nexus&module=support§ion=new
July 29, 201311 yr There are no known security vulnerabilities presently. Even the most recent one we patched (which was in a third party product we ship with IP.Board) would not easily allow your database to be leaked unless your server configuration allowed external connections to MySQL (a pretty bad idea if you are not extremely conscious of how security works in that context). We would encourage you to submit a ticket for assistance so we can help investigate and track down the source of the problem.
Archived
This topic is now archived and is closed to further replies.