This release incorporates several bug fixes reported to us by users. Specific bugs fixed are as follows:
- Long passwords with special characters are not accepted by the upgrader/installer
- Old "ST=#" style topics not redirected to the rewritten URL
- Blog Friendly URLs (IP.Blog built in feature) does not work properly with Community SEO
- Topics in trash can shown in Similar Topics block
- Links from own site can sometimes still be logged in Trackbacks even when configured not to
- "http://1" links sometimes logged in Trackbacks
- Running sitemap task from ACP with rewritting enabled can cause bad links in Sitemap (also see this related and fixed report, this fixed report, and this fixed report)
- getnewpost, getlastpost functions not working correctly.
- Modifications cannot use "boink_it" method before CSEO is loaded (Note: Install instructions updated to fix this, but you do not need to apply the change if you are not experiencing errors - this is just for moving forward)
- Disabling "Display active users in topic" disables the Similar topics, social networking and trackbacks features (Note: Install instructions updated, but you do not need to apply the changes if you have the mentioned setting enabled)
- Bad URL in a signature can cause an IPB Warning regarding parse_url
- Clicking "View Full Version" in lofi page with IPB Portal disabled causes IPB error message
- Similar topics is too restrictive
- Spaces in a topic title can cause the Digg link not to be formatted properly
Important Note: A minor potential XSS vulnerability was reported and fixed in this release as well. It is possible to inject certain HTML through a URL that your browser will parse into your page. This requires several preconditions
1) It only works in IE (and if you use IE7 + IPB 2.2+, IPB makes use of the http-only cookie flag so any attack is extremely limited)
2) It requires you to click on a special crafted link from a malicious user
However, we did feel it prudent to make this known to our customers so you can better determine to perform the above upgrade. There is no known working exploit, and nobody has reported any issues. The user who found this reported it to us openly, and in return we provided him a free license. This same offer stands for anyone who believes they find a vulernability in our software - if you report it to us, and we confirm it as a working exploit, we will provide you a free license for Community SEO. Our customers are very important to us.
For existing customers, you can download the package from your client area, simply upload the files from the main download and run the upgrade routine. Above, there are two bugs which are noted that may require you to make changes to your IPB source files from the installation instructions, however this is only necessary if you are experiencing these issues.
Additionally, there is one issue that we decided to log in our FAQ section rather than update in the instructions. As the issue will be corrected with the upcoming Gallery 2.2 software, we decided it was best left there: Unable to delete Gallery images

Sign In »
Register Now!
Help
This topic is locked


MultiQuote













