www.loqkat-ks.com
Behuni Pjes E komunitetit Ton edhe Ne Facebook Facebook

https://www.facebook.com/urimefestat

Ju faliminderit.


Join the forum, it's quick and easy

www.loqkat-ks.com
Behuni Pjes E komunitetit Ton edhe Ne Facebook Facebook

https://www.facebook.com/urimefestat

Ju faliminderit.
www.loqkat-ks.com
Would you like to react to this message? Create an account in a few clicks or log in to continue.

phpBB v2.0.13 - February 27, 2005

Shko poshtë

phpBB v2.0.13 - February 27, 2005 Empty phpBB v2.0.13 - February 27, 2005

Mesazh nga Binnz Fri Jan 01, 2010 3:32 pm

phpBB v2.0.13 - February 27, 2005

phpBB v2.0.13 - February 27, 2005 Phpbb

What is phpBB?

phpBB is a high powered, fully scalable, and highly customisable open-source bulletin board package. phpBB has a user-friendly interface, simple and straightforward administration panel, and helpful FAQ. Based on the powerful PHP server language and your choice of MySQL, MS-SQL, PostgreSQL or Access/ODBC database servers, phpBB is the ideal free community solution for all web sites.

Who are phpBB?

phpBB are a group of individuals based internationally who believe in opensource software. The project has been stable since its creation in June 2000 without changes in licencing, leadership or corporate associations. Our goals remain unchanged and clear, to continue developing and supporting a stable, free, opensource forum system.

Key Features

  • Supports popular database servers;
  • Unlimited forums and posts;
  • Multiple language interface;
  • Private or public forums;
  • Powerful search utility;
  • Private messaging system;
  • Complete customisation with templates.
phpBB Group announces the release of phpBB 2.0.13, the "Beware of the furries" edition. This release addresses two recent security exploits, one of them critical. They were reported a few days after .12 was released and no one is more annoyed than us, having to release a new version in such a short period of time.

Fortunately both fixes are easy and in each case just one line needs to be edited.

The first issue is critical (session handling allowing everyone gaining administrator rights) and we urge you to fix it on your forums as soon as possible:

Open includes/sessions.php

Find:
Kodi:
if( $sessiondata['autologinid'] == $auto_login_key )
Replace with:
Kodi:
if( $sessiondata['autologinid'] === $auto_login_key )

A second minor issue reported to bugtraq several days ago was the path disclosure bug in viewtopic.php which got fixed by applying the following steps:

Open viewtopic.php

Find:
[code]$message = str_replace('\"', '"', substr(preg_replace('#(\>(((?>([^>
avatar
Binnz
Moderator
Moderator

Postimet : 3827
Points : 549365
Join date : 04/10/2009
Vendbanimi : New Jersey

Mbrapsht në krye Shko poshtë

Mbrapsht në krye

- Similar topics

 
Drejtat e ktij Forumit:
Ju nuk mund ti përgjigjeni temave të këtij forumi