This is a maintenance release for IP.Board 3 and addresses various bugs, security enhancements, and performance improvements.
Major Changes Since 3.0.4
Among many dozens of smaller bugs fixed and performance improvements, the following security enhancements were made:
- SQL and local file include issue fixed. Note: Due to protection within the SQL driver classes, it is very difficult to effectively exploit IP.Board using this attack. Also you need moderator permissions to perform any exploit. We've hardened this code regardless. Also, due to the input cleaning functions IP.Board uses, the local file include is limited to PHP files on the file system as the usual 'null byte' trick is ineffective.
- Internet Explorer XSS Issue due to incorrect attachment handling fixed.
You can download IP.Board 3.0.5 and any applications you have an active license for in the client area. As always, make a backup of your community before proceeding.
Source: Click Here