Skocz do zawartości


[Invisionize.eu] IP.Board 2.3.6 and 3.0.5 Security Update


  • Proszę się zalogować aby odpowiedzieć
Brak odpowiedzi na ten temat

#1 Invisionize.eu

Invisionize.eu

    Powoli zdobywa wiedzę

  • Użytkownicy
  • PipPipPipPipPip
  • 3131 postów
  • Płeć:Nie powiem
  • Wersja:n/a

Napisany 08 marzec 2010 - 16:03

It has come to our attention that there is a possible XSS exploit present in both IP.Board 2.3.6 and 3.0.x. This vulnerability allows the attacker to insert CSS or Javascript into certain BBCodes that is executed when a user displays the page.

Resolution
Please download the relevant zip for your IP.Board. Expand the zip file and upload the file over the copy on your server. No other action is required.

IP.Board 3.0.5
Dodany obrazek 305xss_march10.zip (13.29K)
: 44

IP.Board 2.3.6
Dodany obrazek 236xss_march10.zip (15.61K)
: 17

The main download zips have been updated. If you have downloaded either 2.3.6 or 3.0.5 since the time of this announcement, then you do not need to patch your installation.

Zobacz Artykuł w pełnej wersji


[Invisionize.eu] IP.Downloads 2.3.0 and IP.Nexus 1.0.3 Released , [Invisionize.eu] Rich Text Editor and Firefox 3.6 Patch for IP.Board 2.3.6 , [Invisionize.eu] IPS Company Blog - Demo Updated , [Invisionize.eu] Enhancements to IPS Support and Services , [Invisionize.eu] IP.Board 3.0.x and Applications: End of Life Announcement


1 użytkowników czyta ten temat

0 użytkowników, 1 gości, 0 anonimowych użytkowników