The new phpBB 2.0.17 release fixes some security issues due to XSS and provides additional new features
phpBB 2.0.17 - New release provides security updates
Tutorial for heavily moderated boards
phpBB Download site
phpBB 2.0.17 - New release provides security updates
Tutorial for heavily moderated boards
phpBB Download site
Quote
CHANGE LOG: What has changed in this release?
* Added extra checks to the deletion code in privmsg.php
* Fixed XSS issue in IE using the url BBCode
* Fixed admin activation so that you must have administrator rights to activate accounts in this mode
* Fixed get_username returning wrong row for usernames beginning with numerics
* Pass username through phpbb_clean_username within validate_username function
* Fixed PHP error in message_die function
* Fixed incorrect generation of {postrow.SEARCH_IMG} tag in viewtopic.php
* Also fixed above issue in usercp_viewprofile.php
* Fixed incorrect setting of user_level on pending members if a group is granted moderator rights
* Fixed ordering of forums on admin_ug_auth.php to be consistant with other pages
* Correctly set username on posts when deleting a user from the admin panel
* Added extra checks to the deletion code in privmsg.php
* Fixed XSS issue in IE using the url BBCode
* Fixed admin activation so that you must have administrator rights to activate accounts in this mode
* Fixed get_username returning wrong row for usernames beginning with numerics
* Pass username through phpbb_clean_username within validate_username function
* Fixed PHP error in message_die function
* Fixed incorrect generation of {postrow.SEARCH_IMG} tag in viewtopic.php
* Also fixed above issue in usercp_viewprofile.php
* Fixed incorrect setting of user_level on pending members if a group is granted moderator rights
* Fixed ordering of forums on admin_ug_auth.php to be consistant with other pages
* Correctly set username on posts when deleting a user from the admin panel

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.



Back to top








