Topic: New user gained admin access
I had a user sign up at a forum that I've been running with some people I know...he signed up with a username of "31337", so when I saw that as a new user, I clicked on it, and his profile was showing he was an administrator. I checked the server logs, and I see lots of stuff in there, and that he found the forum searching google for "Powered by punbb 1.2.1".
Are there any known exploits in 1.2.1 that will allow somone to easily gain admin access? Obciusly, I'm going to upgrade from 1.2.1 now, but I'd just like to know for future reference.