Jump to content

IPB 2.1.7 Security Update - Medium Priority

Whether you're a seasoned veteran or a struggling beginner, Web Radiance is the web development and web design forum for you. You'll find answers to all your HTML, CSS, SEO, and Programming needs. Pull up a chair and stay awhile.

Page 1 of 1
  • You cannot start a new topic
  • This topic is locked

IPB 2.1.7 Security Update - Medium Priority Rate Topic: -----

#1 User is offline   ShakingSpirit 

  • Pedantic Whinger
  • Group: Members
  • Posts: 237
  • Joined: 01-August 06
  • Gender:Male
  • Location:Southampton, UK

Posted 21 October 2006 - 11:43 AM

forums.invisionpower.com said:

It has come to our attention that due to the way some browsers interpret image tags a vulnerability exists which allows a malicious user to perform an XSS attack by forcing an "onerror" event in the snapback tag.

To update your board, simply download the attached ZIP file, unarchive it and upload 'sources/classes/bbcode/class_bbcode_core.php' over the one on your server. If you wish to patch your board manually, please read the second post in this announcement.

The main download has been updated as of the time of this announcement.

http://forums.invisionpower.com/index.php?showtopic=227937&pid=1431980&mode=threaded&show=&st=0#entry1431980


Don't know if you've caught this yet, but could be worth patching before a PoC is produced ^_^
QUOTE(MSN)
Benbramz says: i had orgasmic thoughts at the excitement of that
-1

#2 User is offline   Karl Buckland 

  • A.K.A. Sirkent
  • Group: Administrators
  • Posts: 2,145
  • Joined: 04-April 06
  • Gender:Male
  • Location:Kent, UK

Posted 21 October 2006 - 11:51 AM

Arse - they didn't make a new announcement about this, they simply added onto a previous one...

Still, it's updated now. Thanks for the heads up ShakingSpirit!
QUOTE(benbramz @ Aug 17 2007, 07:44 AM) Ive noticed that quite a few people are now adding quotes from the board into their signature. I think its started an new web-radiance craze.. :P
0

#3 User is offline   ShakingSpirit 

  • Pedantic Whinger
  • Group: Members
  • Posts: 237
  • Joined: 01-August 06
  • Gender:Male
  • Location:Southampton, UK

Posted 21 October 2006 - 12:04 PM

Caught me out too, hense why this is 2 days late ^_^

I thought that the previous one was pretty silly; why would an administrator, with 'root' access to the db, need to hack their own board? :blink:

This post has been edited by ShakingSpirit: 21 October 2006 - 12:05 PM

QUOTE(MSN)
Benbramz says: i had orgasmic thoughts at the excitement of that
0

#4 User is offline   marcamos 

  • W.R. General
  • Group: Administrators
  • Posts: 2,849
  • Joined: 04-April 06
  • Gender:Male
  • Location:Massachusetts - USA

Posted 21 October 2006 - 10:53 PM

View PostShakingSpirit, on Oct 21 2006, 01:04 PM, said:

Caught me out too, hense why this is 2 days late ^_^

I thought that the previous one was pretty silly; why would an administrator, with 'root' access to the db, need to hack their own board? :blink:

On a certain Thursday afternoon, when the temperature is between 45 and 47 degrees farenheit, when the sky is grey, and an airplane flies overhead, I can see how it is possible.


:ninja:
0

#5 User is offline   Ben Abrams 

  • The buddy system:never fails
  • Group: Administrators
  • Posts: 1,850
  • Joined: 04-April 06
  • Gender:Male

Posted 22 October 2006 - 06:51 AM

was there not a warning in the admin page of ACP? usually lets you know when there is a critical update.

View PostSirkent, on 21 September 2007 - 04:26 AM, said:

<monty python high-pitched female voice>I DON'T LIKE SPAM!</monty python high-pitched female voice>
0

#6 User is offline   Karl Buckland 

  • A.K.A. Sirkent
  • Group: Administrators
  • Posts: 2,145
  • Joined: 04-April 06
  • Gender:Male
  • Location:Kent, UK

Posted 22 October 2006 - 07:59 AM

View Postbenbramz, on Oct 22 2006, 12:51 PM, said:

was there not a warning in the admin page of ACP? usually lets you know when there is a critical update.


Yes, but it was so soon after we updated the forums with new code (and the previous security update), that I assumed I had forgotten to reset the warning - especially considering the security update in question had been edited - a new update wasn't posted.
QUOTE(benbramz @ Aug 17 2007, 07:44 AM) Ive noticed that quite a few people are now adding quotes from the board into their signature. I think its started an new web-radiance craze.. :P
0

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users