<b>Security Update for IP.Board 3.0.2</b>
It has come to our attention that there are two potential SQL injection vulnerabilities present in IP.Board 3.0 which can be taken advantage of via careful URL crafting.
<b>Resolution</b>
The attached zip contains two files which fix the issue. The files are for IP.Board version 3.0.2 <i>only</i>. Those still running 3.0.0 or 3.0.1 will need to upgrade to 3.0.2 as soon as possible.
The main 3.0.2 download zip was updated at 10:15 am EST August 18, 2009. If you download 3.0.2 after this time: your files are already updated.
Simply download the attached zip file and upload the files contained within to your IP.Board directory on your server. No other action is required.
<a href="http://community.invisionpower.com/index.php?app=core&module=attach§ion=attach&attach_id=19739" target="_blank"><img src="http://community.invisionpower.com/public/style_extra/mime_types/zip.gif" border="0" class="linked-image" /></a>
<a href="http://community.invisionpower.com/index.php?app=core&module=attach§ion=attach&attach_id=19739" target="_blank">180809.zip</a> <b>(13.73K)</b>
: 6103
<i>Support Note:</i> While our technical support department will apply this patch for you on request for those with support service, we strongly suggest you apply this patch yourself whenever possible. Applying the patch is a simple matter of uploading files to your server and, once done, your community is instantly protected without having to wait for our technicians to do the upload for you.
<b>Impacted Versions:</b>
3.0.0
3.0.1
3.0.2 versions downloaded before posted time or unpatched
<b>Not Impacted:</b>
2.0.x
2.1.x
2.2.x
2.3.x
<i>The vulnerability information was purchased by Beyond Security's SecuriTeam Secure Disclosure. The discoverer of the vulnerability requested to remain anonymous. IPS thanks this group for bringing it to our attention.</i>
<a href="http://community.invisionpower.com/topic/291103-invision-power-board-3-0-2-security-update/" target="_blank"><b>Читать дальше...</b></a>
<a href="http://translate.google.com/translate?u=http://community.invisionpower.com/topic/291103-invision-power-board-3-0-2-security-update/&langpair=en%7Cru" target="_blank"><b>Перевод...</b></a>
It has come to our attention that there are two potential SQL injection vulnerabilities present in IP.Board 3.0 which can be taken advantage of via careful URL crafting.
<b>Resolution</b>
The attached zip contains two files which fix the issue. The files are for IP.Board version 3.0.2 <i>only</i>. Those still running 3.0.0 or 3.0.1 will need to upgrade to 3.0.2 as soon as possible.
The main 3.0.2 download zip was updated at 10:15 am EST August 18, 2009. If you download 3.0.2 after this time: your files are already updated.
Simply download the attached zip file and upload the files contained within to your IP.Board directory on your server. No other action is required.
<a href="http://community.invisionpower.com/index.php?app=core&module=attach§ion=attach&attach_id=19739" target="_blank"><img src="http://community.invisionpower.com/public/style_extra/mime_types/zip.gif" border="0" class="linked-image" /></a>
<a href="http://community.invisionpower.com/index.php?app=core&module=attach§ion=attach&attach_id=19739" target="_blank">180809.zip</a> <b>(13.73K)</b>
: 6103
<i>Support Note:</i> While our technical support department will apply this patch for you on request for those with support service, we strongly suggest you apply this patch yourself whenever possible. Applying the patch is a simple matter of uploading files to your server and, once done, your community is instantly protected without having to wait for our technicians to do the upload for you.
<b>Impacted Versions:</b>
3.0.0
3.0.1
3.0.2 versions downloaded before posted time or unpatched
<b>Not Impacted:</b>
2.0.x
2.1.x
2.2.x
2.3.x
<i>The vulnerability information was purchased by Beyond Security's SecuriTeam Secure Disclosure. The discoverer of the vulnerability requested to remain anonymous. IPS thanks this group for bringing it to our attention.</i>
<a href="http://community.invisionpower.com/topic/291103-invision-power-board-3-0-2-security-update/" target="_blank"><b>Читать дальше...</b></a>
<a href="http://translate.google.com/translate?u=http://community.invisionpower.com/topic/291103-invision-power-board-3-0-2-security-update/&langpair=en%7Cru" target="_blank"><b>Перевод...</b></a>