The damage this sort of attack can do is mitigated by IP.Board's use of HTTP-only cookies and other security measures.
As part of our continued dedication to security enhancement, we are releasing a simple patch for IP.Board 3.0.5 to address this issue. If you are running IP.Board versions less than 3.0.5 simply upgrade your software version. Note that this issue does not exist in IP.Board 3.1.0 Beta 2 and beyond.
Download Patch
Simply upload the attached file to: admin/sources/classes/bbcode/custom/defaults.php
defaults.zip (9.67K)
: 29
The main 3.0.5 download zip has been updated as of this date.
Source: Click Here












