LT   EN   RU  
Sunday 2 April 2023 Straipsniai.lt - Independent and informative portal
Home
Phorum
Contacts
Login
Register   Login
News subscribe
Subscribe   Unsubscribe
Partners
www.slaptai.lt www.gamezone.lt
www.penki.lt www.hakeriai.lt
   
   
Advertising
Statistic
Visits since 2002 09 12 - 69670071
Pages in Straipsniai.lt: 40735
  
  Computers > Computer technologies > Hackers
Lankomumo reitingas Print version Print version
phpBB Attachment Mod: new vulnerabilities discovered
Due to two new discovered vulnerabilities and the release of phpBB 2.0.11 a new attachment mod version has been released.
Please update your Attachment Mod to version 2.3.11 as soon as possible. You are able to use the changed files only package, if you haven't modified any attachment mod files or the patch file package if you are familiar with patch files. For all others the normal package should be sufficient. Please read the provided documentation.

This Mod adds the ability to attach files in phpBB2.
This Version will NOT work with phpBB2 Modules designed for *Nuke Portals. Those working with *Nuke Portals are ports and will be not supported here.

Changes since Version 2.3.10:

* fixed bug in GD/Imagick-Detection (on some installations thumbnailing images did not work)
* Added mysql index to attachment table for larger boards
* updated pre-edited files to be compatible with phpBB 2.0.11
* changed order of uploading files, resulting in hopefully getting the correct filesizes if the server does not allow file access outside the working directory
* added check for config table constant to update script
* fixed overwriting of group_id in admin_groups if Categories Hirarchie mod is installed
* fixed bugs regarding the 4GB limits users experienced
* fixed deletion of thumbnails
* fixed directory traversal injection (high severity) - Paul Laudanski (AKA Zhen-Xjell)
With this an attacker could be able to add/remove/execute files outside of the upload directory
* fixed multiple file extensions vulnerability (high severity) - Jeremy Bae at STG Security, Inc.
Due to the handling of mod_mime on multiple extensions an attacker is able to upload arbitrary script files to the web server.

If you need help, please first look at the Attachment Mod User Guide.

The new paskage can be obtained from:
http://www.phpbb.com/phpBB/catdb.php?mode=download&id=436728  or
http://sourceforge.net/project/showfiles.php?group_id=66311
 

         
Lankomumo reitingas

Diskusijos - Discusions

Versija spausdinimui - Print version

Atgal
Random tags:    PHP (3)    Agriculture (17)    Computer games (64)    Computer piracy (10)    Narcotics no (13)    Gymnastics (9)    Heathendom (3)    Medicine (5)    Astrology (10)    Ecology (10)    Fantasy (10)    Formula 1 (2)    Transport (54)    Wedding (10)    Operating systems (19)    Programing (13)    Sound systems (10)    Badminton (3)    Mother and child (17)    People (56)    Economics2 (2)    Travels (2)    Physics (5)    Mysticism (119)    Aviculture (2)    Tourism (46)    Business (25)    Internet (4)    History (4)    Art (10)    Sport (81)    Eurointegration (4)    Communication (38)    Egypt (43)    Philosophy (2)    Mobile communication (9)    Suckling (10)    Politics (13)    Automobiles (10)    Modems (2)    Computers (355)    Aviation (10)    Viruses (10)    Software (11)    Biology (66)    Nursing (4)    Monitors (10)    Paintball (10)    Skydiving (10)    Hobby (25)
1. Bill Gates and other communists
2. Wi-Fi overtakes Ethernet for home networks
3. Worm plays games with victims
4. McAfee Launches SiteDigger 2.0 - program, which checks sites for their vulnerabilities
5. Troy-horses infects Windows Media files?
6. iWork productivity software targets Microsoft's Office
7. Taiwan police seize 60,000 suspect AMD CPUs
8. IDC: 3 future technologies
9. Windows XP SP2 Firewall shows your files and printers to every Internet user
10. Multiple vulnerabilities within PHP <= 4.3.9, PHP5 <= 5.0.2
1. Multiple vulnerabilities within PHP <= 4.3.9, PHP5 <= 5.0.2
2. Taiwan police seize 60,000 suspect AMD CPUs
3. Who says safe computing must remain a pipe dream?
4. Bill Gates and other communists
5. iWork productivity software targets Microsoft's Office
6. Feds try to take logs from Nmap creator
7. McAfee Launches SiteDigger 2.0 - program, which checks sites for their vulnerabilities
8. New Internet domains in the works
9. Windows XP SP2 Firewall shows your files and printers to every Internet user
10. Kazaa creates worst spyware threat, says CA
Map