Skip to content

Possible Vulnerability #1165

Description

@masodo

I am currently running 2 instances of Geeklog CMS 2.2.2 in a php 8.2.28 environment.

I have been debugging along the way due to several incompatibilities and have been having great success running these websites.

Today I noticed that both of these websites were hacked with identical attacks that created a ".html" file in the sites' root folders.

The pages themselves are pretty innocuous but do represent do be an "0wn3d" situation. I am running several other NON-Geeklog sites on the same server which are not victims, so I feel confident in saying that something in Geeklog might be facilitating the hack.

Not sure if this is the place to begin digging-in to the trouble. but am wondering if anyone has any idea what might be the root of the problem?

I have read about possible trouble in admin/trackback.php and am not happy with permissions for the GUS plugin so am starting my investigations there. Is anyone else running Geeklog and getting hit with this likely "Transversal" hack/attack?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions