PHPFusion v6.01.19 upgrade for v6.01.18
Posted by starefossen on 11/28/2009
We have just been informed about a very serious MySQL injections in the latest version of PHPFusion v6, PHPFusion v7 is perfectly safe and this injection do not harm any sites running PHPFusion v7 only those still using PHPFusion v6. The new package includes a fix for the MySQL vulnerability in members_poll_panel.php as described in this thread.

The presently released packages are up to date with the present version of the SVN (1423) and the downloads on SourceForge have been updated.

Upgrading is performed by unzipping the upgrade package, uploading the contents to your webserver and run the upgrade script from Admin Panel -> System Admin -> Upgrade.

PHPFusion 6.01.19 Update - for 6.01.18 only (3.1 Kcool.
PHPFusion 6.01.19 (2.2 Mcool.

PHPFusion v6 is no longer developed and we suggest everyone having a site using PHPFusion v6 to upgrade to PHPFusion v7 for a better experience and security!

Credits:
Thanks a lot to our users; smokeman, for detecting and reporting on this vulnerability, and slaughter for helping providing a fix for it.