HEADS UP: Forum sec update

Fórumok

HEADS UP: Forum sec update

Hozzászólások

Par nappal ezelott megjelent a phpBB 2.0.12-es verzioja, amely egy rakas biztonsagi frissitest tartalmaz:

* Added confirm table to admin_db_utilities.php
* Prevented full path display on critical messages
* Fixed full path disclosure in username handling caused by a PHP 4.3.10 bug - AnthraX101
* Added exclude list to unsetting globals (if register_globals is on) - SpoofedExistence
* Fixed arbitrary file disclosure vulnerability in avatar handling functions - AnthraX101
* Fixed arbitrary file unlink vulnerability in avatar handling functions -AnthraX101
* Removed version number from powered by line
* Merged database update files to update_to_latest.php file
* Fixed path disclosure bug in search.php caused by a PHP 4.3.10 bug (related to AnthraX101's discovery)
* Fixed path disclosure bug in viewtopic.php caused by a PHP 4.3.10 bug - matrix_killer

Ennek megfeleloen en is frissitettem a HUP-on futo verziot. Ha valaki rendellenesseget talal a forum mukodeseben, kerem jelezze itt. Feature request-eket most nem kerek!