Hosted by the
SW:Rebellion Network
phpNuke, phpBB, and other scripts Expert -
Evaders Squadron Coding - Coding Services
Home
Forums
Nuke Patched Core
Coding Services
Webmaster Services
Personal
Login/Create an Account
Forums
·
Forums FAQ
·
Search
·
Usergroups
·
Profile
·
Private Messages
Support Us
This site runs with your support. Please donate:
User Info/Login
Welcome,
Anonymous
Nickname
Password
Security Code:
Type Security Code
(
Register
)
Membership:
Latest:
as7apcool
New Today:
0
New Yesterday:
3
Overall:
6732
People Online:
Visitors:
12
Members:
0
Total:
12
Link to Us
Affliates
Evaders Squadron Coding [ESC] :: View topic - Security: phpBB 2.0.22 Remote PM Delete XSRF Vulnerability
Security: phpBB 2.0.22 Remote PM Delete XSRF Vulnerability
Evaders Squadron Coding [ESC] Forum Index
->
Coding Services
View previous topic
::
View next topic
Author
Message
Evaders99
Joined: Jan 11, 2002
Posts: 3041
Location: USA
Posted: Tue Jan 29, 2008 1:24 am
Post subject: Security: phpBB 2.0.22 Remote PM Delete XSRF Vulnerability
In response to this vulnerability, I am releasing a fix
http://www.securityfocus.com/archive/1/487004/30/0/threaded
This applies to all users of phpBB 2.0.22 as well as all phpNuke forums using BBToNuke 2.0.22
Fix is for all phpBB / Nuke Patched / Nuke Patched Core / RavenNuke
(Different file names, same code)
phpBB 2.0.22 -
privmsg.php
phpNuke -
modules/Private_Messages/index.php
See code changes here:
http://www.swrebellion.com/evaders99/phpbb2022_csrf_fix.txt
Or for the visual version
http://evaders.swrebellion.com/modules.php?name=NukeWrap&page=cvsrepos/modules/Private_Messages/index.php
and click "Diff to previous 1.12"
_________________
Evaders99
Webmaster
Administrator
Fighting is terrible, but not as terrible as losing the will to fight.
-
SW:Rebellion Network
-
Evaders Squadron Coding
-
Back to top
Display posts from previous:
All Posts
1 Day
7 Days
2 Weeks
1 Month
3 Months
6 Months
1 Year
Oldest First
Newest First
Evaders Squadron Coding [ESC] Forum Index
->
Coding Services
All times are GMT - 5 Hours
Page
1
of
1
Jump to:
Select a forum
Nuke Patched Core
----------------
Nuke Patched Core 7.6/7/8 + 7.5
Nuke Patched Core Testers
Services
----------------
Coding Services
Webmaster Services
Public Comments
Personal
----------------
Anything else
You
cannot
post new topics in this forum
You
cannot
reply to topics in this forum
You
cannot
edit your posts in this forum
You
cannot
delete your posts in this forum
You
cannot
vote in polls in this forum
Powered by
phpBB
© 2001, 2005 phpBB Group
^Top
Home
Your Account
Forums
Downloads
F.A.Q.
Submit News
Hosting
Contact Us
© 2005 - 2007 by Evaders99. All Rights Reserved.
All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters.
You can syndicate our news using the file
backend.php
PHP-Nuke
Copyright © 2005 by Francisco Burzi. This is free software, and you may redistribute it under the
GPL
.
PHP-Nuke comes with absolutely no warranty, for details, see the
license
.
Page Generation: 0.41 Seconds