Archive For July, 2007

The latest news happening at July, 2007, directly to your doorstep from The Staff Lounge. Don't forget to checkout what else we have to offer by browsing our interactive online archive page too.


Archive for July, 2007



UseBB 1.0.7 “vulnerability”

UseBB

Yesterday (July 20th, 2007), a post was made on the popular Bugtraq mailing list about a so-called vulnerability in UseBB 1.0.7. This vulnerability includes an insecure value of PHP’s PHP_SELF variable being used in forms in three old upgrade scripts that can be exploited for an "XSS attack". However, unlike the report states, this vulnerability should be rated far from "dangerous".The vulnerability is found in upgrade scripts which were used to upgrade a few old versions of UseBB, being 0.2.3, 0.3 and 0.4. The latter one was released almost 2.5 years ago. Second, this vulnerability poses zero security threats to…

UseBB 1.0.7 “vulnerability”

UseBB

Yesterday (July 20th, 2007), a post was made on the popular Bugtraq mailing list about a so-called vulnerability in UseBB 1.0.7. This vulnerability includes an insecure value of PHP’s PHP_SELF variable being used in forms in three old upgrade scripts that can be exploited for an "XSS attack". However, unlike the report states, this vulnerability should be rated far from "dangerous".The vulnerability is found in upgrade scripts which were used to upgrade a few old versions of UseBB, being 0.2.3, 0.3 and 0.4. The latter one was released almost 2.5 years ago. Second, this vulnerability poses zero security threats to…

Tags: comments, release

PHP Group support of PHP4 ending (updated 07/09/2007) (6 replies)

Phorum

I thought I would comment here for our users that still use PHP4. PHP4 support will end some time in 2008. The exact date is not yet known. That means no security or feature changes after that date. PHP4 is already in a non-announced security fix only state.Phorum is more than ready for the latest PHP5 versions. The dev team all use PHP5 (5.2 in most cases). If you have control of it, I suggest you start migrating your code now. If you don’t have control, I recommend you complain asap to your host.Furthermore, Phorum 5.2 will not guarantee compatibility…

Tags: Phorum, test, testing

UseBB 1.0.7 released

UseBB

I am happy to announce version 1.0.7 of the light and Open Source PHP/MySQL bulletin board package "UseBB".Version 1.0.7 is a minor feature enhancements and bug fix release. Changes include but are not limited to:- added an (random math based or custom) anti-spam question feature against spam bots;- added a security measure which generates a new session ID when logging in/out;- fixed a few minor bugs found since version 1.0.6.Upgrading is highly recommended. Visit http://www.usebb.net/downloads/ for downloads. Information about upgrading is available in the docs/index.html document.This release also features a small gain in performance. 1.0.7 uses only 92% of 1.0.6’s…

UseBB 1.0.7 released

UseBB

I am happy to announce version 1.0.7 of the light and Open Source PHP/MySQL bulletin board package "UseBB".Version 1.0.7 is a minor feature enhancements and bug fix release. Changes include but are not limited to:- added an (random math based or custom) anti-spam question feature against spam bots;- added a security measure which generates a new session ID when logging in/out;- fixed a few minor bugs found since version 1.0.6.Upgrading is highly recommended. Visit http://www.usebb.net/downloads/ for downloads. Information about upgrading is available in the docs/index.html document.This release also features a small gain in performance. 1.0.7 uses only 92% of 1.0.6’s…

Tags: comments, features, release

Looking for user documentation writers (no replies)

Phorum

For Phorum 5.2, the Phorum team has started to setup a structured documentation system. We want to provide documentation for several audiences: administrators, users (which includes moderators) and developers. A preview of this documentation system can be found here: [secretsauce.phorum.org]We would like to invite the users of Phorum to help us with writing the user documentation part. As you can see in the above page, that part is still quite empty. Please let us know if you are interested and have time to work on this project. Once we have a couple of documentation writers (or just one fanatic writer…

Tags: Phorum, write



Delve Deeper

Extra Stuff

You are currently browsing the The Staff Lounge weblog archives for July, 2007.

Longer entries are truncated. Click the headline of an entry to read it in its entirety.

Powered By

Living Off

Forums Powered By vBulletin Blog Powered By Wordpress Skin Designed By Binary Bonsai