Jump to content


Welcome to IPS!

Feel free to browse our community to get a feel for how our community software operates. Post in the pre-sales forum with any questions you have before purchasing or use the Test Posting forum to post a few messages yourself! You can also get a free demo to try the IPS Community Suite yourself.

Already an active IPS client?

Login with the same email address and password you use for the client area to access client-only areas.

* * * * - 10 votes

IP.Board 2.3.6 and 3.0.5 Security Update


  • Please log in to reply
1 reply to this topic

#1 IPS News

IPS News

    Public Relations

  • IPS Staff
  • 712 posts

Posted 08 March 2010 - 09:34 AM

It has come to our attention that there is a possible XSS exploit present in both IP.Board 2.3.6 and 3.0.x. This vulnerability allows the attacker to insert CSS or Javascript into certain BBCodes that is executed when a user displays the page.

Resolution
Please download the relevant zip for your IP.Board. Expand the zip file and upload the file over the copy on your server. No other action is required.

IP.Board 3.0.5
Attached File  305-march-10.zip   35.55K   1368 downloads

Please note this patch will only work with IP.Board 3.0.5. If you are using an earlier version of IP.Board 3.0 then you will need to upgrade to IP.Board 3.0.5. After you have upgraded, you will not need to add this patch.

IP.Board 2.3.6
Attached File  236xss_march10.zip   15.61K   1970 downloads

The main download zips have been updated. If you have downloaded either 2.3.6 or 3.0.5 since the time of this announcement, then you do not need to patch your installation.

#2 Matt

Matt

    Chief Software Architect

  • IPS Management
  • 25,487 posts

Posted 18 March 2010 - 10:30 AM

Patch Update for IP.Board 3.0.5

We have been working over the past week with Aoyagi Ritsuka on hardening the code for several BBCode tags. I have attached a new zip in the original post for IP.Board 3.0.5 which contains the original fix plus improvements in security in other tags which will prevent future exploits from being successful.

This patch also includes a fix for a minor issue with hidden redirect scripts being able to remove user's avatars and/or photos.

As usual, please download the zip file, expand and upload the files over the copies on your server. No further action is required.

The main download zip has been updated at the time of this post.

Note: Zip file was updated at 16:30 GMT to fix a platform specific issue.
Matthew Mecham ( TwitterPersonal BlogFlickr )
Invision Power Services, Inc. - C.S.A.
Email | Official IPS Facebook Page | 434-316-7201
"I love deadlines. I especially like the whooshing sound they make as they go flying by."
-- Douglas Adams (1952 - 2001)




1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users