<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title>PHPDeveloper.org</title>
    <link>http://www.phpdeveloper.org</link>
    <description>Up-to-the Minute PHP News, views and community</description>
    <language>en-us</language>
    <pubDate>Wed, 19 Jun 2013 22:42:55 -0500</pubDate>
    <ttl>30</ttl>
    <item>
      <title><![CDATA[Internet Storm Center: Invision Power Board Vulnerability]]></title>
      <guid>http://www.phpdeveloper.org/news/5493</guid>
      <link>http://www.phpdeveloper.org/news/5493</link>
      <description><![CDATA[<p>
In a <a href="http://isc.sans.org/diary.php?storyid=1350&isc=37ffa6909ceaca9d2bd2832b0ac9a1d7">previous post</a> on the Internet Storm Center website, they mentioned an issue that had come up with the Invision Board PHP/MySQL message board system by which a user clicking on a certian kind of link would push a .wmf exploit to the user.
</p> 
<p>
More information about the exploit and the updates that the Invision Board team have made to counteract it can be found <a href="http://forums.invisionpower.com/index.php?showtopic=215527">in this board pasting</a>.
</p>
<p>
Unfortunately, there has also already <a href="http://isc.sans.org/diary.php?storyid=1375&rss">been an incident</a> with the exploit, causing the boards of "a large company" that was using it as a forum for its customers. Links started showing up that were causing problems, redirecting users to another server's page that pushed the bad .wmf file to them.
</p>
<p>
If you are running an Invision Board version before 2.1.6, it is <a href="http://forums.invisionpower.com/index.php?showtopic=215527">stringly suggested you upgrade</a>.
</p>]]></description>
      <pubDate>Thu, 01 Jun 2006 14:59:35 -0500</pubDate>
    </item>
  </channel>
</rss>
