GnuBoard Product Security Update Advisory

Overview

 

S.I.R.S. Soft has released an update to address a vulnerability in its GnuBoard product. users of affected versions are advised to update to the latest version.

 

Affected Products

 

GnuBoard versions prior to 5.5.16

 

Resolved Vulnerabilities

 

SQL Injection and file upload vulnerabilities in GnuBoard

 

Vulnerability Patches

 

Vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

GnuBoard 5.5.16 at least

 

checks and actions

 

o Check and delete the following PHP files and other malicious files on the server

– Malicious file name : auto_n.php

– Malicious file installation path

1. /gnuboard4/adm/img/[ttttt, pill, poll, etc. random characters]/auto_n.php

2. /adm/mail/img/[ttttt, pill, poll, etc. random characters]/auto_n.php

o After checking, update to the latest version of GnuBoard (5.5.16 at least)

 

Referenced Sites

 

[1] https://www.krcert.or.kr/kr/bbs/view.do?searchCnd=&bbsId=B0000133&searchWrd=&menuNo=205020&pageIndex=1&categoryCode=&nttId=71433