| Author |
Post |
|
|
#1 Thu Apr 12, 2007 12:01 pm
|
|
Developer
Registered: Apr 2004
Posts: 2163
Location: Belgium
|
The UseBB Team is happy to announce version 1.0.6 of the light and Open Source PHP/MySQL bulletin board package "UseBB". Version 1.0.6 is a minor security and bug fix release. Changes include but are not limited to: - fixed a full path disclosure vulnerability; - fixed a bug that posed problems when setting certain time zones; - fixed more bugs in the SQL Toolbox and ACP Modules panes of the ACP. Upgrading is highly recommended. Visit http://www.usebb.net/downloads/ for downloads. Information about upgrading is available in the docs/index.html document. The discovered security vulnerability (full path disclosure) only occurs on PHP setups with register_globals enabled and certain GET or POST variables passed to the system, resulting into an error containing the script's full path on the web server. This vulnerability itself cannot be exploited directly, but the disclosed information may be abused by people with system access. Thanks to Jesper Jurcenoks of netVigilance, Inc. for reporting this. Their security advisory can be found at http://www.netvigilance.com/advisory0016. « Last edit by Dietrich on Wed Apr 25, 2007 1:49 pm. »
|
|
|
#2 Thu Apr 12, 2007 12:48 pm
|
|
Member
Registered: May 2005
Posts: 314
Location: Washougal, WA.
|
Well done, thanks Dietrich. Now if I can only download it, seems SF is down.
|
|
|
#3 Thu Apr 12, 2007 12:53 pm
|
|
Developer
Registered: Apr 2004
Posts: 2163
Location: Belgium
|
Works here, perhaps you should choose a different download mirror?
|
|
|
#4 Thu Apr 12, 2007 12:56 pm
|
|
Member
Registered: May 2005
Posts: 314
Location: Washougal, WA.
|
All I get is Failure To Connect To Web Server, even SF logo image here doesn't load.
|
|
|
#5 Thu Apr 12, 2007 3:17 pm
|
|
Developer
Registered: Apr 2004
Posts: 2163
Location: Belgium
|
I guess it must be something local. Perhaps it has been solved now?
|
|
|
#6 Thu Apr 12, 2007 8:26 pm
|
|
Member
Registered: May 2005
Posts: 314
Location: Washougal, WA.
|
Got it, worked all the sudden.
|
|
|
#7 Fri Apr 27, 2007 5:01 pm
|
|
Member
Registered: Apr 2007
Posts: 29
Location: Haifa, IL
|
Good Luck! _______________ Best Regards,
|
|
|
#8 Mon Jun 04, 2007 5:01 am
|
|
Member
Registered: Jun 2007
Posts: 4
|
Good Luck ! With 2.0
|
|
|
#9 Mon Jul 02, 2007 8:49 pm
|
|
Member
Registered: Jul 2007
Posts: 20
Location: Hatfield, UK (Lithuania)
|
Nice boards, I see. I will translate the package to Lithuanian.
|