Discuss: MyBB 1.2.4 Released - Important Security Update
#60
theman80 Wrote:I have version 1.2.2.
What if I make only the following change on my forum?
Is that enough?

=====================
2. inc/functions.php
=====================

Find:
--
	return $ip;
}
--

ABOVE it add:
--
	global $db;
	$ip = $db->escape_string(preg_replace("#([^.0-9 ]*)#", $ip, ""));
--

=====================
DONE
=====================

I would suggest upgrading to MyBB 1.2.3 first - get the changed file at: http://community.mybboard.net/showthread.php?tid=16273 , if you really don't want to upgrade, you can use the attachment in that thread (http://community.mybboard.net/showthread.php?tid=16273) to fix the security issue found in MyBB 1.2.2 and then apply the MyBB 1.2.4 patch.



Messages In This Thread
RE: Discuss: MyBB 1.2.4 Released - Important Security Update - by Chris W. B. - 2007-04-04, 10:13 PM

Forum Jump:


Users browsing this thread: 1 Guest(s)