A webmaster forum specifically catering for Australian site owners. We discuss site development, marketing and management issues.
Please welcome our newest member, mmmmmu!
Spice up your web site with the ultimate community message board solution!
Fake Id'sGet fake Id's made right now!
vBSEOSearch Engine Optimization for your VBulletin Forum.
AdminFusion
»
[IPB News] IP.Board 2.2.x Security Update
| | #1 |
| | |||||
| Title: Apprentice Join Date: Sep 2005 Posts: 443 ![]() | We have been notified that a vulnerability exists in the profile updating functions of IP.Board 2.2.0 - IP.Board 2.2.2. Although the vulnerability cannot change any authentication credentials such as the email address or password and the vulnerability cannot be used to craft XSS (cross site scripting) attacks it can be used to cause a nuisance by updating another user's AIM name, Yahoo! identity, et. cetera. The update (attached) is a single file update to "sources/action_public/xmlout.php". Manual patch instructions are also supplied. The main download zip has been updated at the time of this announcement. We would like to thank "iMMENSE" for bringing this to our attention. More... | ||||
| |
| | #2 |
| | #4 |
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| Display Modes | |
| |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| [IPB News] IPB 2.1.x Security Update Notice (06-30-2006) | Industry News | Invision Power Board | 3 | 07-03-2006 03:03 PM |
| [IPB News] IPB 2.x.x Security Update (06-05-6) | Industry News | Invision Power Board | 0 | 05-17-2006 07:07 PM |
| [IPB News] IPB 2.x.x Security Update (04-25-06) | Industry News | Invision Power Board | 0 | 04-25-2006 04:08 PM |
| [IPB News] IPB 2.1.5 Security Update (03-08-06) | Industry News | Invision Power Board | 0 | 03-09-2006 01:05 AM |
| [IPB News] IPB 2.x.x Critical Security Update | Industry News | Invision Power Board | 0 | 01-05-2006 10:08 PM |
