Jump to content

Welcome to DevFuse Forums

Sign In  Log in with Facebook

Create Account
Welcome to DevFuse Forums, like most online communities you must register to view or post in our community, but don't worry this is a simple free process that requires minimal information for you to signup. Be apart of DevFuse Forums by signing in or creating an account.
  • Start new topics and reply to others
  • Subscribe to topics and forums to get email updates
  • Get your own profile page and make new friends
  • Send personal messages to other members.
Guest Message by DevFuse

(View All Products)Featured Products

  • Donations

    Help fund your forum with donations, setup goals and track member donations. Offer rewards for members donating.
  • Timeslips

    Have your members submit their race times and share with others.
  • Videos

    Allows your members to submit their own videos for community viewing. Support is included for all the major video sites.
  • Forms

    Build your own forms for your members without coding experience. Support included for pm, email and topics.
  • Collections

    Build a community database of items for your members. Full features custom fields included.


IP.Board Security Enhancements

  • Please log in to reply
No replies to this topic

#1 Michael



  • Management
  • 3,561 posts
  • Gender:Male
  • IP.Board Version:IPB 3.4.x

Posted 12 September 2007 - 09:02 AM

IP.Board Security Enhancements

We are releasing three minor security updates to address issues recently reported regarding areas of IP.Board 2.3.1. These security issues are rather low priority and require specific sets of circumstances to be utilized. Even then the impact is minimal due to other security features in the software.

Issue 1 (Reported by http://www.turkish-media.com/forum/ )

If you use a character set other than iso-8859-1 or utf-8, it is possible to submit javascript to your user profile fields. The potential damage is mitigated by the use of httpOnly cookies in IP.Board. Please note that IP.Board ships with iso-8859-1 set by default. Therefore, unless you have specifically changed the character set in the Admin CP your installation is not impacted by this issue.

Issue 2 (Reported by http://www.criticalsecurity.net/ )

A user is able to upload a non-image file if the file is given an image name in a specific format. The security implications are very low because IP.Board automatically resets the file to a .txt file and treats it as such, however this could result in broken photo or avatar images being displayed, and script files with a .txt extension saved in your uploads directory. Again the potential damage is mitigated by the use of httpOnly cookies in IP.Board thereby disallowing javascript access to cookies.

Issue 3 (Reported by http://communityseo.com/forums/ )

If you have subscription packages enabled on your site using the subscriptions manager included with IP.Board which promote a paying user to a new user group, it is possible to recraft a payment form to set the member's ID to a different member. The issue would require that an actual valid payment is made and no unauthorized access could be gained, however a specially crafted form could result in all administrators/moderators of a site being demoted to a subscriber group, for example. The reverse, a user being promoted to admin, is not possible in this issue.

Patching Your IP.Board

The IP.Board 2.3.1 download in the client area has already been updated with the required changes. If you download IP.Board after the date of this announcement your installation will be up to date.

Changed Files
Download the zip file below which includes only the changed files for this update. Simply upload and overwrite the old files.


Manual Instructions
The following file contains manual patch instructions for those who want to edit php files by hand.


Source: Click Here

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users