Results 1 to 5 of 5

Thread: phpBB upgrade to 2.09

  1. #1
    Regular Member darlin's Avatar
    Join Date
    Jun 2004
    Posts
    251

    phpBB upgrade to 2.09

    For all phpBB users, phpBB upgraded to version 2.09 to address several vulnerabilities and general fixes.
    What has changed in this release?

    This changelog is included with all archives:



    Fixed one vulnerability in admin_board.php - Xore

    Added checking for proper session id characters to sessions and viewtopic to prevent injections - Bartlomiej Korupczynski

    Fixed injection vulnerabilities possible with linked avatars

    Implemented unsetting globalised variables

    Limited confirm switch to POST variable in posting

    Changed IP code in common.php to prevent IP spoofing

    Updated visual confirmation mod [pre-edited files]

    Moved obtaining word censors in modcp out of topic generation loop [increased performance/lower query count] - spotted by R45

    Added the ability to link to https/ftps sites using the img bbcode tag

    Fixed user online information in admin/index.php

    Fixed getting group moderator in groupcp.php if running oracle backend - spotted by pakman

    Fixed use of non-existing result variable in modcp (poster_id instead of user_id)

    Fixed several vulnerabilities (XSS, SQL Injection and path disclosure) only possible with register_globals enabled - Matthew C. Kavanagh, Janek Vind

    Fixed problem with SID not delivered to next page in groupcp.php
    Looking for a superior web host? Try the one I've used for 3years, LunarPages

  2. #2
    Good Guy waferdog's Avatar
    Join Date
    May 2000
    Location
    Head of the Lakes
    Posts
    668

    Unhappy

    Thanks for the info.

    Have you upgraded before? Which method do you use? Specifically, do you have mods installed?

    I have a lightly modded 2.0.6 board. I have been hesitant to upgrade up to this point due to the mods. Any experiences? Any advice?

  3. #3
    Regular Member darlin's Avatar
    Join Date
    Jun 2004
    Posts
    251
    Quote Originally Posted by waferdog
    Thanks for the info.

    Have you upgraded before? Which method do you use? Specifically, do you have mods installed?

    I have a lightly modded 2.0.6 board. I have been hesitant to upgrade up to this point due to the mods. Any experiences? Any advice?
    I use the changed file package. After I unzip, I find my version, for example 2.06_to_2.09.zip, and I unzip it to a folder I created on my PC. Also, when you first unzip the changed file package, there will be 4 folders: cache, contrib, docs and install. You will want to upload those folders, and overwrite the exsiting ones.
    *Note* Do not delete your config.php file.

    You'll want to open each of the folders that is in the zip file, 2.06 _to_2.09 directory, and select all the files, and upload those files to the corresponding directory on your server, since all files did not change, the folders only consist of the changed files. After you finish uploading all of the changed files, you will need to navigate to your forum, and add this to the end of the url: install/update_to_209.php. This will upgrade your forum.


    If you have any mods, some may be gone after the upgrade, but if you have any mods that you had to create tables for, the tables will still be there. The only thing you will need to do is just mod the files again and upload them.

    Just take your time getting the mods added back. It shouldn't take that long, but don't get in rush.
    Looking for a superior web host? Try the one I've used for 3years, LunarPages

  4. #4
    Good Guy waferdog's Avatar
    Join Date
    May 2000
    Location
    Head of the Lakes
    Posts
    668
    Well, I have been thinking of using the patch upgrade method, as that seems designed for folk with mods, but of course that is a new process for me.

    I have also had the thought of waiting for phpBB 2.2 to come out and upgrade then.

    One of these I will make a decision.

  5. #5
    Regular Member darlin's Avatar
    Join Date
    Jun 2004
    Posts
    251
    Quote Originally Posted by waferdog
    Well, I have been thinking of using the patch upgrade method, as that seems designed for folk with mods, but of course that is a new process for me.

    I have also had the thought of waiting for phpBB 2.2 to come out and upgrade then.

    One of these I will make a decision.
    If the upgrade didn't consist of fixes for vulnerabilities, I'd wait too, but since there's a few on there that concern me, I would upgrade.
    Looking for a superior web host? Try the one I've used for 3years, LunarPages

Similar Threads

  1. XP- new vs. upgrade
    By arethereanyleft in forum Software Forum
    Replies: 5
    Last Post: 05-23-04, 05:33 PM
  2. AMD Upgrade help
    By Dunster in forum Hardware & Overclocking
    Replies: 2
    Last Post: 05-05-04, 07:56 PM
  3. RedHat Linux Upgrade
    By BoOmEr2120 in forum Software Forum
    Replies: 6
    Last Post: 04-29-02, 07:25 PM
  4. windows xp upgrade question????
    By thebigelk in forum General Discussion Board
    Replies: 20
    Last Post: 01-15-02, 09:10 AM
  5. I want to upgrade my 2 yr old computer, is it possible?
    By TeenInternetAddict in forum Hardware & Overclocking
    Replies: 7
    Last Post: 10-23-01, 08:28 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •