4WebHelp
 FAQ  •  Search  •  User Groups  •  Forum Admins  •  Smilies List  •  Statistics  •  Rules   •  Login   •  Register
Toggle Navigation Menu

 Highlighting vulnerability in phpBB 2.x
Post New TopicReply to Topic
View Previous Topic Print this topic View Next Topic
Author Message
Daniel
Team Member



Joined: 06 Jan 2002
Posts: 2564

PostPosted: Fri Nov 22, 2002 6:10 pm (15 years ago) Reply with QuoteBack to Top

All versions of phpBB 2 are affected by this vulnerability. It can be exploited by linking to a forum with malicious code in the query string (something like this: viewtopic.php?id=1234&highlight=malicious code here).

Find out more: http://www.phpbb.com/phpBB/viewtopic.php?p=330627#330627

If you need any help with applying the fix, just ask!

________________________________
Image
OfflineView User's ProfileFind all posts by DanielSend Personal Message
Darren
Team Member



Joined: 05 Feb 2002
Posts: 549
Location: London

PostPosted: Fri Nov 22, 2002 7:41 pm (15 years ago) Reply with QuoteBack to Top

I put the fix in but but I get a parse error.

I'm going to check I didn't miss something, but did you have that problem?
OfflineView User's ProfileFind all posts by DarrenSend Personal MessageVisit Poster's Website
Daniel
Team Member



Joined: 06 Jan 2002
Posts: 2564

PostPosted: Fri Nov 22, 2002 7:44 pm (15 years ago) Reply with QuoteBack to Top

No, I didn't (but then I didn't follow those instructions - I made the changes from CVS). What line is it on? And what is on that line (of course!)?

Otherwise, try downloading the whole viewtopic.php file from CVS, if you don't have any mods in that file.

________________________________
Image
OfflineView User's ProfileFind all posts by DanielSend Personal Message
Darren
Team Member



Joined: 05 Feb 2002
Posts: 549
Location: London

PostPosted: Fri Nov 22, 2002 7:51 pm (15 years ago) Reply with QuoteBack to Top

I took it off as people were using the board Laughing

but I believe it said 451, doesn't look like anything out of place

It might be the last change in the instuctions
its certainly throwing the syntax colouring in my text editor - looks like the php tag
but that might be nothing


Never used CVS before can you point me right at the file, as I'm having trouble finding it?
Thanks
OfflineView User's ProfileFind all posts by DarrenSend Personal MessageVisit Poster's Website
Daniel
Team Member



Joined: 06 Jan 2002
Posts: 2564

PostPosted: Fri Nov 22, 2002 7:55 pm (15 years ago) Reply with QuoteBack to Top

Hi Darren,

Here is the latest version of viewtopic.php from CVS:

http://cvs.sourceforge.net/cgi-bin/viewcvs.cgi/phpbb/phpBB2/viewtopic.php?rev=1.186.2.11&only_with_tag=phpBB-2_0_0&content-type=text/vnd.viewcvs-markup

________________________________
Image
OfflineView User's ProfileFind all posts by DanielSend Personal Message
Darren
Team Member



Joined: 05 Feb 2002
Posts: 549
Location: London

PostPosted: Fri Nov 22, 2002 8:02 pm (15 years ago) Reply with QuoteBack to Top

Thanks!
All seems to be working Very Happy
OfflineView User's ProfileFind all posts by DarrenSend Personal MessageVisit Poster's Website
Display posts from previous:      
Post New TopicReply to Topic
View Previous Topic Print this topic View Next Topic


 Jump to:   




You cannot post new topics in this forum.
You cannot reply to topics in this forum.
You cannot edit your posts in this forum.
You cannot delete your posts in this forum.
You cannot vote in polls in this forum.


Page generation time: 0.051551 seconds :: 17 queries executed :: All Times are GMT
Powered by phpBB 2.0 © 2001, 2002 phpBB Group :: Based on an FI Theme