| | #1 |
| Forum Guru Join Date: Sep 2005
Posts: 8,309
![]() | <b>IP.Board 2.3.4 Security Enhancements and DST Bug Fix</b><br /><br />We are releasing a minor security update to address issues recently reported regarding areas of IP.Board 2.3.4. These security issues are rather low priority and the impact is minimal due to other security features in the software. We would like to thank the users and administrators of <a href="http://www.criticalsecurity.net/" target="_blank">criticalsecurity.net</a> for their help in identifying the issues and testing the patches.<br /><br /><b>Issue</b><br /><br />Nesting custom bbcode in an improper fashion can result in the final HTML result of the bbcode being broken, and subsequently unwanted HTML injected into the tag. If used in specific fashions, a person could inject javascript event handlers into the final result. Additionally, we have added an "allowscriptaccess" parameter to flash movies parsed in IPB to prevent flash movies and avatars from having javascript access. These issues are mitigated due to the use of httpOnly cookies in IP.Board which limits the direct impact.<br /><br />Additionally, we have patched a recent bug with the automated DST checking in IPB that has surfaced since the recent DST changeover.<br /><br /><b>Patching Your IP.Board</b><br /><br />The IP.Board 2.3.4 download in the client area has already been updated with the required changes. If you download IP.Board after the date of this announcement your installation will be up to date.<br /><br /><b>Changed Files</b><br /><br />Download the zip file below which includes only the changed files for this update. Simply upload and overwrite the old files.<br /><br /><a href='http://forums.invisionpower.com/index.php?act=attach&type=post&id=16364'>http://forums.invisionpower.com/index.php?act=attach&type=post&id=16364</a><br /> More... |
| | |
| | #2 |
| Rookie | TIP: Actually look at what is in that white box you type in. LMAO
__________________ To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. |
| | |
| | #3 |
| Forum Junkie ![]() | FAILING: They're doing it right!
__________________ Ack, no currently active projects To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts. |
| | |
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| Display Modes | |
| |
