ALERT - Security hole in Zenphoto 184.108.40.206 09 November 2011
We urge anyone to upgrade to Zenphoto 220.127.116.11 if still on 18.104.22.168 or older. The ajax file manager included in earlier versions had a security hole. This is 3rd party tool by phpletter.com we use for non gallery file management as a plugin for our text editor TinyMCE and standalone on the admin backend upload tab.
This security hole had been reported (ticket #2005) and fixed in 22.214.171.124. But since the last days several security sites flooded the web and twitter with notes about that we sadly learnt that someone apparently has been exploiting it hacking some sites now (we don't know what exactly this hack does):
So if you encounter the symtoms described in these forum topics please upgrade immediatly following our upgrade instructions and also check your custom themes or plugins if you use such.