Forum Moderators: rogerd
Here's a quick summary of the security issue changes from 2.0.12 to 2.0.13:
OPEN sessions.php
FIND
* $Id: sessions.php,v 1.58.2.11 2004/07/11 16:46:19 acydburn Exp $
REPLACE WITH
* $Id: sessions.php,v 1.58.2.12 2005/02/27 20:33:01 acydburn Exp $
FIND
if( $sessiondata['autologinid'] == $auto_login_key )
REPLACE WITH
if( $sessiondata['autologinid'] === $auto_login_key )
OPEN viewtopic.php
FIND
* $Id: viewtopic.php,v 1.186.2.38 2005/02/21 18:37:06 acydburn Exp $
REPLACE WITH
* $Id: viewtopic.php,v 1.186.2.39 2005/02/27 20:33:00 acydburn Exp $
FIND
$message = str_replace('\"', '"', substr(preg_replace('#(\>(((?>([^><]+¦(?R)))*)\<))#se', "preg_replace('#\b(" . $highlight_match . ")\b#i', '<span style=\"color:#" . $theme['fontcolor3'] . "\"><b>\\\\1</b></span>', '\\0')", '>' . $message . '<'), 1, -1));
REPLACE WITH
$message = str_replace('\"', '"', substr(@preg_replace('#(\>(((?>([^><]+¦(?R)))*)\<))#se', "@preg_replace('#\b(" . $highlight_match . ")\b#i', '<span style=\"color:#" . $theme['fontcolor3'] . "\"><b>\\\\1</b></span>', '\\0')", '>' . $message . '<'), 1, -1));
SAVE AND CLOSE ALL FILES