nBill Community nBill Home Page
22/May/2012, 11:05:26 PM *
Welcome, Guest. Please login or register.

Login with username, password and session length
News: Click Here for the nBill home page, or take a tour.  
 
   Home   Help Search Login Register  
Pages: [1]
  Print  
Author Topic: Cross Site Scripting Vulnerability Affecting ALL Editions of nBill  (Read 367 times)
netshine
Administrator
Hero Member
*****
Offline Offline

Posts: 4,563


View Profile
« on: 13/July/2011, 10:39:57 AM »

A cross site scripting (xss) vulnerability has been discovered, affecting ALL versions of nBill. Whilst this is not a critical problem and is unlikely to result in the compromise of your site or any client data, it is nevertheless recommended that you apply the relevant patch from the replies below (I will reply to this topic once for each edition of nBill).

The main component download files have all been patched, so if you download the component after 10:40am BST on 13th July 2011, you do not need to apply the patch.

To apply the patch, simply replace your /components/com_nbill/nbill.php file with the relevant attachment below (in the case of nBill 1, the file to replace is /components/com_netinvoice/netinvoice.php).
Logged
netshine
Administrator
Hero Member
*****
Offline Offline

Posts: 4,563


View Profile
« Reply #1 on: 13/July/2011, 10:41:38 AM »

For nBill 2.1.1 (Standard Edition), please use the attached file (it is the same file regardless of which version of Joomla or Mambo you are using).

* nbill.php (28.79 KB - downloaded 42 times.)
Logged
netshine
Administrator
Hero Member
*****
Offline Offline

Posts: 4,563


View Profile
« Reply #2 on: 13/July/2011, 10:42:52 AM »

For nBill 1.2_10 (Standard Edition), please use this file.

* netinvoice.php (58.04 KB - downloaded 38 times.)
Logged
netshine
Administrator
Hero Member
*****
Offline Offline

Posts: 4,563


View Profile
« Reply #3 on: 13/July/2011, 10:43:43 AM »

For nBill Lite (2.0.10), please use this one.

* nbill.php (12.15 KB - downloaded 34 times.)
Logged
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines Valid XHTML 1.0! Valid CSS!