slot5.net: IP.Board 2.3.6 and 3.0.5 Security Update - slot5.net

Ir a contenido

Página 1 de 1
  • No puedes empezar un nuevo tema
  • No puedes responder a este tema

IP.Board 2.3.6 and 3.0.5 Security Update

#1 El usuario está offline   IPS Icono

  • Advanced Member
  • PipPipPip
  • Grupo: Members
  • Mensajes: 68
  • Registrado: 05 / 09 / 09
  • Location:Barcelona
  • Nacimiento:05-09-2009

Escrito 08 / 03 / 2010 - 15:34

It has come to our attention that there is a possible XSS exploit present in both IP.Board 2.3.6 and 3.0.x. This vulnerability allows the attacker to insert CSS or Javascript into certain BBCodes that is executed when a user displays the page.

Resolution
Please download the relevant zip for your IP.Board. Expand the zip file and upload the file over the copy on your server. No other action is required.

IP.Board 3.0.5
Imagen enviada 305xss_march10.zip (13.29K)
: 224

IP.Board 2.3.6
Imagen enviada 236xss_march10.zip (15.61K)
: 91

The main download zips have been updated. If you have downloaded either 2.3.6 or 3.0.5 since the time of this announcement, then you do not need to patch your installation.View the full article
0

Página 1 de 1
  • No puedes empezar un nuevo tema
  • No puedes responder a este tema

1 usuarios están leyendo este tema
0 miembros, 1 invitados, 0 usuarios anónimos