RE: bug in Invision Power Board

From: Christopher Hummert (hummertc_at_noghri.net)
Date: 08/11/03

  • Next message: G00db0y: "ZH2003-22SA (security advisory): Zorum XSS Vulnerability and Path Disclosure"
    To: <bugtraq@securityfocus.com>
    Date: Mon, 11 Aug 2003 10:42:16 -0700
    
    

    Will someone please tell us what version this is in? 1.2 was released
    last week. Did it fix this problem?

    -----Original Message-----
    From: Boy Bear [mailto:eyal067@walla.co.il]
    Sent: Saturday, August 09, 2003 2:32 PM
    To: bugtraq@securityfocus.com
    Subject: Re: bug in Invision Power Board

    In-Reply-To: <20030809082131.25004.qmail@www.securityfocus.com>

    To repair Bug to edit the file admin.php and to add after the line:

    $IN['AD_SESS'] = $HTTP_POST_VARS['adsess'] ? $HTTP_POST_VARS['adsess'] :

    $HTTP_GET_VARS['adsess'];

    To add this :

    if (isset($IN['AD_SESS'])) {

            $IN['AD_SESS'] = htmlspecialchars($IN['AD_SESS']);

    }


  • Next message: G00db0y: "ZH2003-22SA (security advisory): Zorum XSS Vulnerability and Path Disclosure"

    Relevant Pages

    • [Un] Unangband 0.6.3 released
      ... Allow player to assemble friendly monsters and carry eggs to hatch ... Updated druidic spells to use new region code. ... Fix lockup bugs generating the Old Forest. ... Fix bug where items dropped by monster death would infinitely ...
      (rec.games.roguelike.announce)
    • please pull from the trivial tree
      ... Fix spelling in E1000_DISABLE_PACKET_SPLIT Kconfig description ... +- Finding patch that caused a bug ... +Always try the latest kernel from kernel.org and build from source. ... Length of input string in bytes ...
      (Linux-Kernel)
    • Subterrane v0.194 Alpha Released
      ... system, a character sheet, a ton of new spells, new monsters, item ... Added a character sheet that displays your character's ... Fix: Fixed a bug in the encumbrance calculation and status display ...
      (rec.games.roguelike.announce)
    • Re: Larkin, Power BASIC cannot be THAT good:
      ... If they did not produce a product with *adequate* quality then customers would not buy it and the company would not make a profit. ... it is to change a product in the field, and Y axis is bug density. ... but when the in service fix is almost free to the supplier then they will exploit that to their advantage. ... On-screen programming is pretty much type and ignite and see what ...
      (sci.electronics.design)
    • Unangband 0.6.2-wip7a has been released
      ... This release is mostly a bug fix revision to wip7, however, I was able ... You can now use the run command to 'step' into an adjacent monster, ... The player only suffers a monster disease if the monster disease ... Fix up some animal speech sayings. ...
      (rec.games.roguelike.announce)

  • Quantcast