Security update
Date: Monday, January 31, 2005 @ 9:19 AM CST
Topic: Security Advisory


I have released a security update which came to my attention yesterday. Information relating to the security issue is below. Affected: PHP-Nuke 6.5-7.6 / PHP-Nuke Platinum 6.9.0-7.6.0 / PHP-Nuke Patched 2.8 / phpBB 2.0.11. Description: phpBB administrative variable manipulation can allow illegal server path disclosure. Correction method: Available here

@ chatserv: might like to apply this in patched 2.9.

I updated 2.8, 2.9 is not yet ready, one change from your suggested fix though, delete modules/Forums/Admin/common.php instead of editing it, if any file is making a call to this one it should be edited to point to the main one. Thanks for the heads up bro.



This article comes from Nuke Resources
http://www.nukeresources.com

The URL for this story is:
http://www.nukeresources.com/modules.php?name=News&file=article&sid=966