ALERT - Security hole in Zenphoto 22.214.171.124 November 09, 2011
We urge anyone to upgrade to Zenphoto 126.96.36.199 if still on 188.8.131.52 or older. The ajax file manager included in earlier versions had a security hole. This is 3rd party tool by phpletter.com we use for non gallery file management as a plugin for our text editor TinyMCE and standalone on the admin backend upload tab.
This security hole had been reported (ticket #2005) and fixed in 184.108.40.206. But since the last days several security sites flooded the web and twitter with notes about that we sadly learnt that someone apparently has been exploiting it hacking some sites now (we don't know what exactly this hack does):
So if you encounter the symtoms described in these forum topics please upgrade immediatly following our upgrade instructions and also check your custom themes or plugins if you use such.
For questions and comments please use the forum or discuss on the social networks.