Forum Moderators: rogerd
See the announcement here: [phpbb.com...]
...The first issue is critical (session handling allowing everyone gaining administrator rights) and we urge you to fix it on your forums as soon as possible...
You can download it here: [phpbb.com...]
Just wanted to alert you guys,
Elijah
"If you're tired of upgrading all the time"
Upgrades are required when a security issue is discovered. Hopefully you don't think forum x, y, or z are immune to such issues, and will not require upgrades? Yabb has escaped serious attention because it has fewer installs, once crackers start focusing on a product it's amazing what they can come up with. Last year crackers werent' all that interested in phpbb, this year they are, and so they started finding holes. Don't fool yourself into thinking a product is secure that is live and online on the web. Some of the recent phpbb security fixes were workarounds for php security issues, for example.
What makes me really tired is having to reinstall a forum that's been hacked, db destroyed, so I'll take a small upgrade anytime over that headache, hopefully the new yabb board will take the same approach, release patches fast when security issues come up.