Discuss all about [IPB] IPB 2.x.x Security Update (04-25-06)

Discuss [IPB] IPB 2.x.x Security Update (04-25-06) at Bulletin Board News, All the latest information from vBulletin, Invision Power Board and phpBB, all put together in some forum for your joy and pleasure. This post outlines the steps required to update your IPB 2.0.x or IPB .





Post New Thread  Reply
 
LinkBack Thread Tools Thread Tools Feed Icon
  #1  
Old 04-26-2006, 09:54 AM
IPB News
TSL Fixated
 
Post Count Posts: 87

This post outlines the steps required to update your IPB 2.0.x or IPB 2.1.x for this security update.
If you've downloaded IPB 2.1.5 since the time of this post, there is no need to update your installation as the main download has been updated.

It has come to our attention that Invision Power Board 2.0.x and Invision Power Board 2.1.x contains potential vulnerabilities:
  • A bug in Internet Explorer 5.0+ which allows a JPEG image to be uploaded with a GIF header containing malicious HTML / javascript code. (IPB 2.1.x only)
  • Potential SQL injection (limited to 32 characters)
  • Potential arbitrary PHP code execution
The attached files below contain the required files to update your installation to protect against these vulnerabilities. Simply download the relevant security update ZIP package and upload the files over the ones in your IPB installation effectively overwriting the files on your server.

Invision Power Board 2.1.x Update Package
http://forums.invisionpower.com/index.php?act=Attach&type=post&id=9981

Invision Power Board 2.0.x Update Package
http://forums.invisionpower.com/index.php?act=Attach&type=post&id=9980
Link To Original Article

Reply With Quote