miniBB ®
 
miniBB Community Forum
 | Forums | File Bank | Sign Up | Reply | Search | Statistics | Manual |
Private Messaging addon for miniBB Allow your miniBB-forums members communicate with each other tet-a-tet with the Private Messaging add-on!
News & Announcements miniBB Community Forum / News & Announcements /
Short link for this topic:

RSS addon update - file inclusion vulnerability fix

Author Paul
CEO
#1 | Posted: 13 Jun 2007 12:56 | Edited by: Paul
For those who are using RSS addon, we recommend to install the patch which fixes so known vulnerability when register_globals in PHP is set to ON.

If register_globals is set to OFF, or if you are using Premoderation addon, you don't need to worry.

Else modify the file rss2.php and paste this line BEFORE the line which declares the setting called $premodDir (commented by default):

if(isset($premodDir)) unset($premodDir);
//$premodDir='./shared_files/'; /* If you are using premoderation addon, set/uncomment this option to not display pending messages in the RSS feed. */

Thanks to our user kazim09 who has been reported this issue.
News & Announcements miniBB Community Forum / News & Announcements / RSS addon update - file inclusion vulnerability fix Top
Your Reply Click this icon to move up to the quoted message

» Username  » Password 
You are welcome to post anonymously by entering a nickname with no password (if that nickname has not been taken by another member) or by leaving both fields empty. If you have a forums membership account, you can also sign in from this page without posting a message, or sign in and post at once.


Before posting, make sure your message is compliant with our forum posting rules. If not, it may be locked or deleted with no explanation.

 
miniBB Community Forum Powered by Free Forum Software miniBB ® Features  Requirements  Demo  Download  Showcase  Gallery of Arts
Compiler  Premium Extensions  Premium Support  License  Contacts