Help - Search - Members - Calendar
Full Version: Security Post
Invision Power Services > Community Forums > Community General Chat
WilliamB
To the IPB team:

My apologies if this has been posted already but a quick search didn't turn anything up:

Invision Power Board HTML / TXT Attachment Script Insertion
http://secunia.com/advisories/16348/

(just in case this hadn't been reported to you all yet).

Thanks.
Will L.
this seems to be a new one Matt will have to see this
Alex Duggan
2.0 onwards is not vulnerable.
Will L.
QUOTE(Alex Duggan @ Aug 9 2005, 02:57 PM) *
2.0 onwards is not vulnerable.


thanks for the clarifcation Alex thumbsup.gif
cthree
It says confirmed in 2.0.4 Can you confirm this tongue.gif

I don't allow attachments so not an issue for me.
WilliamB
QUOTE(Alex Duggan @ Aug 9 2005, 02:57 PM) *
2.0 onwards is not vulnerable.



Alex:

Thanks.

At the URL, they specifically mentioned:

"The vulnerability has been confirmed in version 2.0.4 and also reported in version 1.0.3. Other versions may also be affected."


I assume that the 2.0.4 mentioned is incorrect then?

Thanks.
Sebastian Mares
Just came across that page and was also wondering if 2.0.4 is vulnerable or not.
CoU
QUOTE
There isn't a "patch" as such as it's the incorrect way in which IE handles mime-types.

I recommend that you change the attachment types (ACP -> Attachments -> Attachment Types) for: php, txt, htm, html to "unknown/unknown".
powerless
So in the end it did effect 2.0.4?

http://forums.invisionpower.com/index.php?...33;entry1263671
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2008 Invision Power Services, Inc.