Quick Login   
 
Register AdminFusion Tutorials
 
Featured Sponsors


One.com Domain and Hosting


Register
Forum of the Month
Australian Webmaster
fotm

A webmaster forum specifically catering for Australian site owners. We discuss site development, marketing and management issues.

Tag Cloud
Latest Threads
Forum Stats
7,843 Members
164,838 Posts
42 Users Online

Please welcome our newest member, mmmmmu!

Affiliates
Go Back AdminFusion » Getting Started » Software » Invision Power Board » [IPB News] IP.Board 2.2.x Security Update
Welcome to the AdminFusion. AdminFusion is the ultimate resource for forum administrators and moderators. With exclusive articles, interviews with the experts, free downloadable skins, and the revolutionary post exchange system - PostFusion, AdminFusion is the place to go for all of your forum needs.  By joining AdminFusion, you will become part of a thriving admin community and immediately gain access to all of these resources. Registration is fast, simple and absolutely free so please join us today!
Want more than our forums? Try these: Post Fusion Forum Matrix
Old 06-12-2007, 01:30 AM   #1

Title: Apprentice

Points: 4,964, Level: 20Points: 4,964, Level: 20Points: 4,964, Level: 20
Level up: 21%, 86 Points neededLevel up: 21%, 86 Points neededLevel up: 21%, 86 Points needed
Activity: 45%Activity: 45%Activity: 45%

Join Date: Sep 2005

Posts: 443

Industry News is on a distinguished road
 
 
Post [IPB News] IP.Board 2.2.x Security Update

We have been notified that a vulnerability exists in the profile updating functions of IP.Board 2.2.0 - IP.Board 2.2.2.

Although the vulnerability cannot change any authentication credentials such as the email address or password and the vulnerability cannot be used to craft XSS (cross site scripting) attacks it can be used to cause a nuisance by updating another user's AIM name, Yahoo! identity, et. cetera.

The update (attached) is a single file update to "sources/action_public/xmlout.php". Manual patch instructions are also supplied.

The main download zip has been updated at the time of this announcement.

We would like to thank "iMMENSE" for bringing this to our attention.

More...
Reply With Quote
Old 06-17-2007, 05:58 AM   #2

Harlzard's Avatar

Title: Forum Addict

Points: 8,426, Level: 27Points: 8,426, Level: 27Points: 8,426, Level: 27
Level up: 28%, 324 Points neededLevel up: 28%, 324 Points neededLevel up: 28%, 324 Points needed
Activity: 9%Activity: 9%Activity: 9%

Join Date: Jan 2006

Posts: 1,913

Location: Australia

Harlzard is just really niceHarlzard is just really niceHarlzard is just really niceHarlzard is just really niceHarlzard is just really nice
Send a message via MSN to Harlzard  
 
This update has been around for about a month hasn't it? my board is already 2.2.2.
__________________
Metaltera.com :: Breed the Metal
Myspace Profile :: My profile!
Reply With Quote
Old 06-17-2007, 08:05 AM   #3

bdude's Avatar

Title: Forum Addict

Points: 9,275, Level: 28Points: 9,275, Level: 28Points: 9,275, Level: 28
Level up: 29%, 75 Points neededLevel up: 29%, 75 Points neededLevel up: 29%, 75 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: Jul 2006

Posts: 1,629

Location: Australia

bdude has a brilliant futurebdude has a brilliant futurebdude has a brilliant futurebdude has a brilliant futurebdude has a brilliant futurebdude has a brilliant futurebdude has a brilliant futurebdude has a brilliant futurebdude has a brilliant futurebdude has a brilliant futurebdude has a brilliant future
Send a message via AIM to bdude Send a message via MSN to bdude Send a message via Yahoo to bdude Send a message via Skype™ to bdude  
 
The vunerability exists in version 2.2.2
__________________
Reply With Quote
Old 06-17-2007, 10:57 AM   #4

Harlzard's Avatar

Title: Forum Addict

Points: 8,426, Level: 27Points: 8,426, Level: 27Points: 8,426, Level: 27
Level up: 28%, 324 Points neededLevel up: 28%, 324 Points neededLevel up: 28%, 324 Points needed
Activity: 9%Activity: 9%Activity: 9%

Join Date: Jan 2006

Posts: 1,913

Location: Australia

Harlzard is just really niceHarlzard is just really niceHarlzard is just really niceHarlzard is just really niceHarlzard is just really nice
Send a message via MSN to Harlzard  
 
Ahh! thanks, i'll update as soon as possible.
__________________
Metaltera.com :: Breed the Metal
Myspace Profile :: My profile!
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

 
Posting Rules

Similar Threads
Thread Thread Starter Forum Replies Last Post
[IPB News] IPB 2.1.x Security Update Notice (06-30-2006) Industry News Invision Power Board 3 07-03-2006 03:03 PM
[IPB News] IPB 2.x.x Security Update (06-05-6) Industry News Invision Power Board 0 05-17-2006 07:07 PM
[IPB News] IPB 2.x.x Security Update (04-25-06) Industry News Invision Power Board 0 04-25-2006 04:08 PM
[IPB News] IPB 2.1.5 Security Update (03-08-06) Industry News Invision Power Board 0 03-09-2006 01:05 AM
[IPB News] IPB 2.x.x Critical Security Update Industry News Invision Power Board 0 01-05-2006 10:08 PM

AdminFusion

All times are GMT +1. The time now is 10:38 PM. Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0 © 2005-2008 AdminFusion - All Rights Reserved



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72