nBill Community nBill Home Page
22/May/2012, 12:11:17 AM *
Welcome, Guest. Please login or register.

Login with username, password and session length
News: Click Here for the nBill home page, or take a tour.  
 
   Home   Help Search Login Register  
Pages: [1]
  Print  
Author Topic: Security Patch for ALL VERSIONS of nBill  (Read 5409 times)
netshine
Administrator
Hero Member
*****
Offline Offline

Posts: 4,563


View Profile
« on: 05/November/2010, 06:14:50 PM »

A new directory traversal issue has been discovered in nBill, affecting ALL VERSIONS. ALL users of nBill must apply the appropriate patch. I will reply to this topic with the relevant patch files for each version.

Please Note: This vulnerability is currently being actively used by hackers to try to retrieve sensitive information from servers where nBill is running. In most cases, if your server security is tight (open base_dir restriction in effect, or suPHP in use), the effects should not be serious, however it is important that you patch your installation as soon as possible. If you are not already running the latest version (2.0.9 standard edition, 2.0.10 lite edition, or 1.2_10), you must upgrade first, then apply the appropriate patch below.
« Last Edit: 05/November/2010, 06:28:18 PM by netshine » Logged
netshine
Administrator
Hero Member
*****
Offline Offline

Posts: 4,563


View Profile
« Reply #1 on: 05/November/2010, 06:15:51 PM »

For nBill 2.0.9 Standard Edition, please replace the following files with the attached:

/administrator/components/com_nbill/admin.nbill.php
/components/com_nbill/nbill.php

[attachment deleted by admin]
Logged
netshine
Administrator
Hero Member
*****
Offline Offline

Posts: 4,563


View Profile
« Reply #2 on: 05/November/2010, 06:18:10 PM »

For nBill 2.0.10 LITE edition, please replace the following files with the attached:

/administrator/components/com_nbill/admin.nbill.php
/components/com_nbill/nbill.php

[attachment deleted by admin]
Logged
netshine
Administrator
Hero Member
*****
Offline Offline

Posts: 4,563


View Profile
« Reply #3 on: 05/November/2010, 06:24:55 PM »

For nBill 1.2_10, please replace the following files with the attached:

/administrator/components/com_netinvoice/admin.netinvoice.php
/components/com_netinvoice/netinvoice.php

[attachment deleted by admin]
Logged
netshine
Administrator
Hero Member
*****
Offline Offline

Posts: 4,563


View Profile
« Reply #4 on: 05/November/2010, 06:41:58 PM »

For the version 2.1.0 BETA release, please replace the following files with the attached:

/administrator/components/com_nbill/admin.nbill.php
/components/com_nbill/nbill.php

[attachment deleted by admin]
Logged
Antoine
Full Member
***
Offline Offline

Posts: 154


View Profile
« Reply #5 on: 17/November/2010, 02:12:19 AM »

Are the current downloadable versions already patched ?
Logged
netshine
Administrator
Hero Member
*****
Offline Offline

Posts: 4,563


View Profile
« Reply #6 on: 17/November/2010, 11:06:01 AM »

Yes
Logged
snaffle
Jr. Member
**
Offline Offline

Posts: 23


View Profile
« Reply #7 on: 25/November/2010, 09:28:11 AM »

Hi there,

I've just downloaded the patch files for the Standard Edition 2.0.9 and I get the following error on my front end forms after uploading them...

The encoded file /var/www/vhosts/domain.com/httpdocs/components/com_nbill/nbill.php is corrupt.

I've changed the domain name as I didn't want to advertise I'm running nBill if there's a security flaw :-)

Any ideas why I might be getting this message?

Thanks

Nathan
Logged
netshine
Administrator
Hero Member
*****
Offline Offline

Posts: 4,563


View Profile
« Reply #8 on: 25/November/2010, 09:32:35 AM »

One or two people seem to have had problems with downloading the patch files from the forum. This might be because the forum software scrambles the files and puts them back together again for download (works fine for most people though). I suggest you try downloading the whole component (from here: http://www.nbill.co.uk/component/option,com_docman/Itemid,10/task,cat_view/gid,11/), unzip it on your computer, and just upload the nbill.php file.
Logged
snaffle
Jr. Member
**
Offline Offline

Posts: 23


View Profile
« Reply #9 on: 25/November/2010, 10:41:23 AM »

Thanks, those method work fine.
Logged
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines Valid XHTML 1.0! Valid CSS!