Enjoy .Security Update
This post outlines the steps required to update your IPB 2.1.x for this security update.
If you've downloaded IPB 2.1.6 since the time of this post, there is no need to update your installation as the main download has been updated.
It has come to our attention that due to a flaw in the way Internet Explorer handles urlencoded data in URLs, it's possible to craft a malicious URL when adding an avatar to cause an XSS (cross site scripting) vulnerability where, at worst, cookie data can be taken. Additionally, an unrelated flaw may allow moderators to moderate forums that they do not have permission to moderate.
Solution
To prevent further attacks of this kind, we've increased security by checking any URL that is likely to be inserted in an <img> tag.
This security update has a full version number of: 21012.60629.s.
Please read our KB article on how to locate your full version number.
Security update applied
#1
Posted 30 June 2006 - 07:51 PM
#2
Posted 30 June 2006 - 08:10 PM
#3
Posted 30 June 2006 - 08:55 PM
#4
Posted 30 June 2006 - 08:56 PM
#5
Posted 30 June 2006 - 08:57 PM
They do in acp, but i also subscribe to their rss feedWow, do they have an update notification thing or something?
#6
Posted 30 June 2006 - 09:18 PM
#7
Posted 30 June 2006 - 10:34 PM
#8
Posted 30 June 2006 - 10:44 PM
#9
Posted 30 June 2006 - 10:53 PM
You pretty much said the same thing last time, tooThanks for installing the security update Cataliste, your hard work is always appreciated.
#10
Posted 01 July 2006 - 06:04 AM
Way to be on the ball Sock.
#11
Posted 01 July 2006 - 08:06 AM
#12
Posted 01 July 2006 - 06:38 PM
#13
Posted 01 July 2006 - 07:58 PM
Um... am I missing something?
QFE!!!
I said that a few weeks back.
#14
Posted 01 July 2006 - 08:15 PM
#15
Posted 02 July 2006 - 03:20 PM
#16
Posted 02 July 2006 - 03:23 PM
Meh, I couldn't figure out how to restrict dynamic images but keep normal ones. Extensions wouldn't work or something.Oh yea, I thought I reported this exact problem to ShadowLink like months ago.
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users