Forum Moderators: phranque

Message Too Old, No Replies

Drupal update fail on unpatched systems

         

tangor

11:10 am on Jan 7, 2016 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Drupal installations could be out of date and open to attack thanks to a borked update process that flags unpatched platforms as current.

The popular content management system is used by more than a million sites making it a significant target for hackers.

Indeed, in October 2014 attackers took mere hours to compromise untold piles of sites whose admins had failed to apply a patch against a dangerous SQL injection flaw.

Drupal at the time went as far as to proclaim all unpatched sites are considered compromised unless patches were immediately applied.

[theregister.co.uk...]

bill

2:10 am on Jan 10, 2016 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Also discussed here: [webmasterworld.com...]