It has come to our attention that due to a flaw in the way Internet Explorer handles urlencoded data in URLs, it’s possible to craft a malicious URL when adding an avatar to cause an XSS (cross site scripting) vulnerability where, at worst, cookie data can be taken. Additionally, an unrelated flaw may allow moderators to moderate forums that they do not have permission to moderate. Solution This security update has a full version number of: 21012.60629.s. Files that have been changed
Security Update Download If you are running a version previous to 2.1.6, please update to 2.1.6 by downloading the main download zip. Once you’ve performed the update, visit your ACP and click the link under the “Security Update Available” image to reset the image check. Manual Instructions http://forums.invisionpower.com/index.php?act=Attach&type=post&id=10132
If you’ve downloaded IPB 2.1.6 since the time of this post, there is no need to update your installation as the main download has been updated.
To prevent further attacks of this kind, we’ve increased security by checking any URL that is likely to be inserted in an <img> tag.
Please read our KB article on how to locate your full version number.
Invision Power Board 2.1.x
Search
About This Entry
- You’re currently reading “IPB 2.1.x Security Update Notice (06-30-2006),” an entry on The Staff Lounge
- Published at 6.30.06 / 12pm





No Responses to “IPB 2.1.x Security Update Notice (06-30-2006)”
Please Wait
Leave a Reply