[x] Navigation

[x] Languages

[x] Design
Each user can view the site with a different theme.
Themes marked with a * also change the forum look.

Wichtig unbedingt lesen Gefahr

This forum is locked: you cannot post, reply to, or edit topics.    This topic is locked: you cannot edit posts or make replies.    Printer Friendly Page     Forum Index ›  Allgemeines

View previous topic :: View next topic  
Author Message
spoddig
Doppel-Null-Agent
Doppel-Null-Agent

Offline Offline
Joined: May 19, 2004
Posts: 208

PostPosted: 21.11.2004 22:51
Post subject: Wichtig unbedingt lesen Gefahr

Hier erstmal ein Link da findet Ihr genaueres das CPG ist auch betroffen habe den mist schon geändert auf der cpgnuke.com gibt es ein Update
www.heise.de/newsticke...dung/53499


spoddig please enter your server specs in your user profile! Crying or Very sad
Back to top
View user's profile Visit poster's website
spoddig
Doppel-Null-Agent
Doppel-Null-Agent

Offline Offline
Joined: May 19, 2004
Posts: 208

PostPosted: 21.11.2004 22:55
Post subject: Re: Wichtig unbedingt lesen Gefahr

Hier der text von CPGNUKE.com
CRITICAL SECURITY BULLETIN

Following my original post here regarding the recent phpBB search highlighting exploit, the phpBB Group has become aware that the exploit can be taken advantage of, in a serious way. This clearly contradicts what I said in my original post, but this IS serious folks. We cannot urge you strongly enough to apply the fix below. This fix does NOT pertain to CPG-Nuke 9, it is immune because of our new quote handling system.

Note: If you applied the earlier fix for .htaccess, keep it - it's a good security measure to take.

The Patch

Open up modules/Forums/viewtopic.php

Find on line ~514:
PHP:
$words = explode(' ', trim(htmlspecialchars(urldecode($HTTP_GET_VARS['highlight']))));


Replace with:
PHP:
$words = explode(' ', trim(htmlspecialchars($HTTP_GET_VARS['highlight'])));


Note: If you see a <?php in the above code snippets, ignore it - it's a bug that we are trying to trace.

If you prefer to upload a patched copy of the file, you will find it below...


Please do take this seriousely, this is a critical issue. Spread the word to as many people as you possibly can that are using CPG-Nuke!

As always, thank you for your continued support of CPG-Nuke.

External Links

www.phpbb.com/p...p?t=240513

www.phpbb.com/p...p?t=240636


spoddig please enter your server specs in your user profile! Crying or Very sad
Back to top
View user's profile Visit poster's website
Reha
Agent
Agent

Offline Offline
Joined: Apr 20, 2004
Posts: 87
Location: Stuttgart
PostPosted: 27.11.2004 14:43
Post subject: Re: Wichtig unbedingt lesen Gefahr

thx


Reha please enter your server specs in your user profile! Crying or Very sad
Back to top
View user's profile ICQ Number MSN Messenger Photo Gallery
Ertan
Webmaster
Webmaster

Offline Offline
Joined: Mar 19, 2004
Posts: 1264
Location: Germany
PostPosted: 28.11.2004 12:37
Post subject: Re: Wichtig unbedingt lesen Gefahr

ist ein phpbb bug

und nicht cpgnuke Wink

aber wichtig patch einspielen

_________________
.: USE THE FORCE :.
Helft mit ! Keine Unbeantworteten Beiträge mehr

Ertan's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Back to top
View user's profile Send e-mail Visit poster's website Photo Gallery
Display posts from previous:   
This forum is locked: you cannot post, reply to, or edit topics.    This topic is locked: you cannot edit posts or make replies.    Printer Friendly Page    Forum Index ›  Allgemeines
Page 1 of 1
All times are GMT + 1 Hour



Jump to:  


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum




Interactive software released under GNU GPL, Code Credits, Privacy Policy