PHP-Nuke Patched
Date: Friday, October 31 @ 14:53:49 CET
Topic: Security


The latest patch for PHP-Nuke
Just about all variables have been secured against sql injection by running a check on their content before inserting anything into the database tables and after having extracted anything from them as well, any module that had not been secured before has been included as well as all admin files. Most files have been converted to the new abstraction layer, i will do my best to finish the ones the are not yet converted this week, time at which i should be back full time.
Since i have had no real chance to test these files you should make a backup of your current files before uploading these.
Downloads:
Nuke 6.0 - Nuke 6.5 - Nuke 6.6-6.8 - Nuke 6.9 & Nuke 7.0 (This last version is not the full pack, 7.0 can be downloaded at phpnuke.org).

I can't stress this enough, make a backup before doing anything, the files have not been tested.

These patches are only online to let others know what is headed their way, do not use them for now as they have been reported to have errors.



This article comes from NukeCops
http://www.nukecops.com

The URL for this story is:
http://www.nukecops.com/modules.php?name=News&file=article&sid=912