Invision Power Services: IPB 2.1.x Security Update Notice (06-30-2006) - Invision Power Services

Jump to content

Subscribe for Updates

Enter your email on our company home page sign up box to subscribe to our company mailing list to receive notifications when we post new announcements along with other news and updates!
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

IPB 2.1.x Security Update Notice (06-30-2006) Rate Topic: -----

#1 User is offline   IPS News Icon

  • Public Relations
  • Icon
  • View blog
  • Group: IPS Staff
  • Posts: 176
  • Joined: 23-September 04
  • Gender:Male

Posted 30 June 2006 - 04:53 PM

Security Update


This post outlines the steps required to update your IPB 2.1.x for this security update.
If you've downloaded IPB 2.1.6 since the time of this post, there is no need to update your installation as the main download has been updated.


It has come to our attention that due to a flaw in the way Internet Explorer handles urlencoded data in URLs, it's possible to craft a malicious URL when adding an avatar to cause an XSS (cross site scripting) vulnerability where, at worst, cookie data can be taken. Additionally, an unrelated flaw may allow moderators to moderate forums that they do not have permission to moderate.

Solution
To prevent further attacks of this kind, we've increased security by checking any URL that is likely to be inserted in an <img> tag.

This security update has a full version number of: 21012.60629.s.
Please read our KB article on how to locate your full version number.


Files that have been changed
  • sources/action_public/moderator.php
  • sources/ipsclass.php
  • sources/lib/func_usercp.php
  • sources/classes/bbcode/class_bbcode_core.php
Security Update Download
Invision Power Board 2.1.x

Download Now

If you are running a version previous to 2.1.6, please update to 2.1.6 by downloading the main download zip. Once you've performed the update, visit your ACP and click the link under the "Security Update Available" image to reset the image check.

Manual Instructions

Attached File  update_instructions_21012.60629.s.html (5.38K)
Number of downloads: 7809


0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users