The widespread vBulletin CMS has a vulnerability that allows remote attackers to create new administrative accounts. Back in August, users of versions in the 4.1+ and 5+ series were advised to delete the /install/ or /core/install/ directories (depending on version) as a workaround against the bug, but vBulletin didn't advise of …
Shirly deleting the installation stuff is the very first thing you do with any script after a successful install?
I can't see why the script can't just do this itself, many other CMS scripts have done so for years or nagged you to death everytime you login to the admin panel.
Even "lowly" OSS apps like phpBB refuse to run if the install directory exists. In fact, phpBB shuts down the forum if the install directory exists. Someone deserves a major boot to the nads for this idiocy. Even moreso since this product costs $$$.
- +Comment Anti-Facebook Ello: Here's why we're still in beta. SPAMGASM!
- NASA rover Curiosity drills HOLE in MARS 'GOLF COURSE'
- WHY did Sunday Mirror stoop to slurping selfies for smut sting?
- Business is back, baby! Hasta la VISTA, Win 8... Oh, yeah, Windows 9
- George Clooney, WikiLeaks' lawyer wife hand out burner phones to wedding guests