Quick Login   
 
Register AdminFusion Tutorials
 
Featured Sponsors


One.com Domain and Hosting


Register
Forum of the Month
Australian Webmaster
fotm

A webmaster forum specifically catering for Australian site owners. We discuss site development, marketing and management issues.

Tag Cloud
Latest Threads
Forum Stats
8,073 Members
165,866 Posts
38 Users Online

Please welcome our newest member, masood!

Affiliates
Go Back AdminFusion » Getting Started » Software » Other Software » MyBB 1.1.8 Released
Welcome to the AdminFusion. AdminFusion is the ultimate resource for forum administrators and moderators. With exclusive articles, interviews with the experts, free downloadable skins, and the revolutionary post exchange system - PostFusion, AdminFusion is the place to go for all of your forum needs.  By joining AdminFusion, you will become part of a thriving admin community and immediately gain access to all of these resources. Registration is fast, simple and absolutely free so please join us today!
Want more than our forums? Try these: Post Fusion Forum Matrix
Old 08-30-2006, 12:52 PM   #1

Belloman's Avatar

Title: Apprentice

Points: 3,643, Level: 17Points: 3,643, Level: 17Points: 3,643, Level: 17
Level up: 18%, 207 Points neededLevel up: 18%, 207 Points neededLevel up: 18%, 207 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: May 2006

Posts: 431

Location: Central Ohio, USA

Belloman is a name known to allBelloman is a name known to allBelloman is a name known to allBelloman is a name known to allBelloman is a name known to allBelloman is a name known to all
 
 
MyBB 1.1.8 Released

Quote:
Originally Posted by Chris Boulton
Due to 3 low risk browser based cross-site scripting vulnerability found in MyBB, we're releasing a security update to the MyBB 1.1.x series. The vulnerabilities include:
  • Avatar / Attachment script insertion vulnerability (only affects users using Internet Explorer and directly accessing a malformed avatar or attachment
  • Cross-site scripting vulnerability on Admin CP login form (imei Web Security)
  • [url] tag cross site scripting vulnerability with unicode and malformed URL (imei Web Security)

We recommend all users upgrade their copy of MyBB to the latest available release.

The release on the MyBB site has also been updated to 1.1.8.

Update instructions are in the next post, including a list of changed files (and a ZIP archive of them) as well as manual patching instructions for those of you who have customized their code.

Beta testers running 1.2: You're only affected by the first vulnerability (IE specific). Please see the beta forum for an updated beta release.

Warning to web application developers:
The first vulnerability affects many web applications. You need to ensure that if you allow file uploads (such as images) that you're correctly checking the file upload type, the actual image type and the file extension.

The vulnerability is performed by spoofing the headers of an uploaded image and providing it with a different filename which causes Internet Explorer to locally execute any markup in the image.

You can read more at SecuriTeam - Microsoft Internet Explorer 6.0 Embedded Cross Site Scripting (GIF) and phpBB (and other BB systems) cookie disclosure exploit.
Hopefully this is the last before 1.2
__________________
RCTgo - SHARE. DISCUSS. EXPLORE.
Justin S. / MyBB Wiki Lead / RCTgo.net
Reply With Quote
Old 08-31-2006, 04:56 AM   #2

Title: Member

Points: 1,487, Level: 10Points: 1,487, Level: 10Points: 1,487, Level: 10
Level up: 11%, 63 Points neededLevel up: 11%, 63 Points neededLevel up: 11%, 63 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: Aug 2006

Posts: 74

harmor is on a distinguished road
 
 
I'm glad to see it's actively developed.
Didn't they have like a dozen XSS vulnerabilities already?
__________________
Xen Web
Offering FREE ad-free hosting with features such as cpanel, fantastico, PHP and MySQL support, and more
Reply With Quote
Old 08-31-2006, 12:41 PM   #3

Belloman's Avatar

Title: Apprentice

Points: 3,643, Level: 17Points: 3,643, Level: 17Points: 3,643, Level: 17
Level up: 18%, 207 Points neededLevel up: 18%, 207 Points neededLevel up: 18%, 207 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: May 2006

Posts: 431

Location: Central Ohio, USA

Belloman is a name known to allBelloman is a name known to allBelloman is a name known to allBelloman is a name known to allBelloman is a name known to allBelloman is a name known to all
 
 
Quote:
Originally Posted by harmor View Post
I'm glad to see it's actively developed.
Didn't they have like a dozen XSS vulnerabilities already?
Well, they've had many security releases previously. The hope is that MyBB 1.2 will be a much more stable product when shipped than the MyBB 1.0x and 1.1.x series, after the development team rewriting a lot of old, bad code, which is probably where a lot of the vulnerabilities came from. But of course, MyBB stays on top of it all, quickly fixing any vulnerabilities and releasing a fix rather than putting them all together in one.

Edit: I'd also like to note that most of the hackings that I'm aware of happened after a fix was released for the security hole, on non-updated boards.
__________________
RCTgo - SHARE. DISCUSS. EXPLORE.
Justin S. / MyBB Wiki Lead / RCTgo.net
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

 
Posting Rules

Similar Threads
Thread Thread Starter Forum Replies Last Post
MyBB 1.2.1 Released - Maintenance & Security Update Release Belloman Other Software 0 09-27-2006 11:52 PM
myBB 1.2 released! Kem Rixen Other Software 13 09-05-2006 05:53 PM
Chris B - MyBB Owner Ryan Interviews 9 08-23-2006 07:06 AM
MyBB 1.1.5 Released IMPAQ Other Software 5 06-30-2006 06:43 PM
MyBB 1.0 Released miner Software 0 12-12-2005 11:56 AM

AdminFusion

All times are GMT +1. The time now is 04:56 AM. Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0 © 2005-2008 AdminFusion - All Rights Reserved


From:
Title:

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72