Jump to content

Welcome to DevFuse Forums

Sign In  Log in with Facebook

Create Account
Welcome to DevFuse Forums, like most online communities you must register to view or post in our community, but don't worry this is a simple free process that requires minimal information for you to signup. Be apart of DevFuse Forums by signing in or creating an account.
  • Start new topics and reply to others
  • Subscribe to topics and forums to get email updates
  • Get your own profile page and make new friends
  • Send personal messages to other members.
Guest Message by DevFuse

(View All Products)Featured Products

  • Donations

    Help fund your forum with donations, setup goals and track member donations. Offer rewards for members donating.
  • Timeslips

    Have your members submit their race times and share with others.
  • Videos

    Allows your members to submit their own videos for community viewing. Support is included for all the major video sites.
  • Forms

    Build your own forms for your members without coding experience. Support included for pm, email and topics.
  • Collections

    Build a community database of items for your members. Full features custom fields included.


IPB 2.x.x Security Update (06-05-16)

  • Please log in to reply
1 reply to this topic

#1 Michael



  • Management
  • 3,530 posts
  • Gender:Male
  • IP.Board Version:IPB 3.4.x

Posted 17 May 2006 - 03:56 AM

This post outlines the steps required to update your IPB 2.0.x or IPB 2.1.x for this security update.
If you've downloaded IPB 2.1.6 since the time of this post, there is no need to update your installation as the main download has been updated.

It has come to our attention that Invision Power Board 2.0.x and Invision Power Board 2.1.x contains two areas where malicious code could be executed. One area requires moderator access and other other requires a carefully crafted POST or GET request. Even though we've not been successful in expoiting IPB 2.1.6 using these methods in our own trials, we felt it best to strengthen security in these areas.

This discovery is based on research from Gulftech.org, a leading security company, and as such has not had full public disclosure.

This security update has a full version number of: 21012.60516.s.
Please read our KB article on how to locate your full version number.

Invision Power Board 2.1.6 Update Package (21012.60501 to 21012.60516)
If you are running a version previous to 2.1.6, please update to 2.1.6 by downloading the main download zip.
Once you've performed the update, visit your ACP and click the link under the "Security Update Available" link to reset the image check.
Download Now

Invision Power Board 2.0.4 Update Package (20014.00000 to 20014.60516)
Download Now

Invision Power Board 2.1.6 Manual Patch Instructions

Source: Click Here

#2 Michael



  • Management
  • 3,530 posts
  • Gender:Male
  • IP.Board Version:IPB 3.4.x

Posted 17 May 2006 - 06:03 PM

Invision Fuse has been patched, must say extremely easy one to patch this one was, also includes manual instructions for you boards with lots of modifications.

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users