The BoardMod Project
 The Project | News | Downloads | Mods | FAQ | Templates | Chat | Forum
Mod Download Database

CategoryYaBB VersionSort ByMods/Page    Search
              
1 Mods Available
Pages: [1] Mod Admin
Name Version req. YaBB Upload Date Author Download Clicks
Security Patch 5/24/07 1.0 2.1 13.06.07 Boris Tjuvanov (MF-B), Jeffrey Man (Jet Li) Security_Patch_05[...] 1183
Description: This security mod will fix your forum so it cannot be hacked by a current
or registering forum member.

The vulnerability allows members to enter specific text into some profile
form fields to gain administrator access to the forum. Administrator rights
grants the member access to the forum controls.

After installing this mod, the user will not be able to use this
vulnerability any more. It converts these form fields to their HTML
equivalent and removes line breaks, rather than writing them directly
to the profile data (.vars) file.

Installation:
1) Modify YaBB files using BoardMod or manually.
2) Load modified files to your server in ASCII mode.

Sources/Profile.pl (ASCII)
Sources/Register.pl (ASCII)
Pages: [1] Mod Admin


If you have problems to download any of these files then check the following:
  • Disable any download manager
  • Use the right mouse button and use "Save Target As..."
  • If nothing helps, you can access to mod folder manually here.


SourceForge.net Logo

© 2000-2007 by - All rights reserved.

 The Project | News | Downloads | Mods | FAQ | Templates | Chat | Forum