Subject: New development version fixes security issue
I was reported a possible remote code exploit in UNB 1.6 Patch 1 and likely also previous versions (not sure about 1.5.x). The attacker needs to have a board account though and register_globals must be on for the bug to be exploited. The only change to fix this bug is the following in unb_lib/abbc.conf.php, around line 635:
As soon as I find the time to finish work on version 1.6.2, there will be a "stable branch" version with all of those things fixed. But you can use the latest development version, too, as it is mainly the same as 1.6.1 Patch 1 and seems to run stable.
Go to the download page.
- ...
- // Smiley Definitions
- // Insert the following two lines:
- $ABBC['Config']['smileset'] = '';
- if ($ABBC['Config']['smileset'])
- {
- ...
As soon as I find the time to finish work on version 1.6.2, there will be a "stable branch" version with all of those things fixed. But you can use the latest development version, too, as it is mainly the same as 1.6.1 Patch 1 and seems to run stable.
Go to the download page.
♪ ...nanananah, all in all we’re just brilliant thieves, nanananah... ♪♬

Yves
Show profile
Link to this post