Jump to content


- - - - -

IPB 2.x.x Security Update (04-25-06)


This topic has been archived. This means that you cannot reply to this topic.
No replies to this topic

#1 IPS News

IPS News

    Spam Happy

  • IPS Staff
  • 766 posts

Posted 25 April 2006 - 07:58 AM

This post outlines the steps required to update your IPB 2.0.x or IPB 2.1.x for this security update.
If you've downloaded IPB 2.1.5 since the time of this post, there is no need to update your installation as the main download has been updated.

It has come to our attention that Invision Power Board 2.0.x and Invision Power Board 2.1.x contains potential vulnerabilities:
  • A bug in Internet Explorer 5.0+ which allows a JPEG image to be uploaded with a GIF header containing malicious HTML / javascript code. (IPB 2.1.x only)
  • Potential SQL injection
  • Potential arbitrary PHP code execution
The attached files below contain the required files to update your installation to protect against these vulnerabilities. Simply download the relevant security update ZIP package and upload the files over the ones in your IPB installation effectively overwriting the files on your server.

Invision Power Board 2.1.5 Update Package
If you are running a version previous to 2.1.5, please update to 2.1.5 by downloading the main download zip.
Attached File  ipb215_su250406.zip   25.55K   37757 downloads

Invision Power Board 2.0.x Update Package
Attached File  ipb200_su250406.zip   20.91K   4240 downloads