Go Back   vBulletin Modification Discussions > Site Business > News and Announcements > Jelsoft vBulletin Announcements
Home Register FAQ Members List Calendar Mark Forums Read
vBSEO Info Tags

Reply
 
LinkBack Thread Tools
Old 11-08-2006, 09:08 PM   #1 (permalink)
Administrator
 
Code Monkey's Avatar
 
Join Date: May 2006
Posts: 2,203
Code Monkey is on a distinguished road
iTrader: (0)
Post vBulletin 3.5.6 Released

vBulletin 3.5.6



An undocumented behaviour in all Windows versions of Internet Explorer has rendered vBulletin vulnerable to a potential cross-site scripting flaw (XSS). Therefore, we have decided to put out a preventative security release in order to work-around the Internet Explorer problem before it is exploited.



We recommend that all customers still running a 3.5 board upgrade to 3.5.6 or apply the patch discussed in this post as soon as possible. Note that our current recommended release is 3.6.3 and we recommend customers upgrade to that!



Performing a full upgrade to 3.5.6 also contains several bug fixes, including a fix for a compatibility issue in PHP 5.2.0. Additionally, this version adds HttpOnly cookies, which helps reduce the amount of damage that could be caused by a potential XSS flaw.



Updating your vBulletin to combat the XSS flaw:



Please note that this issue is present in other versions of vBulletin as well. Please see the appropriate announcement!



Our primary recommendation for customers is to upgrade to vBulletin 3.6.3, but if you are not ready to do this, you can do one of the following:
  1. Full Upgrade: The best way to fix the problem is to perform a full upgrade, downloading the complete 3.5.6 package from the vBulletin Members' Area and following the regular upgrade instructions.
  2. Patch: A second option is to download the patch files discussed in this thread and upload them to your web server, overwriting the existing files. The patch is available in the Members' Area patch page or later in this post!





Link To Original Article

__________________
Please do not PM me unless it's personal. General vBulletin or mod questions by PM will be ignored.

Try the vBSEO Demo

Click here for Instant Community
Code Monkey is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links

Reply
Tags: , ,





Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On


A vBSkinworks Design Recoded By vBModder.
All Code Distributed On This Site is © 2006 by it's author.
Search Engine Optimization by vBSEO 3.1.0

All times are GMT -7. The time now is 02:03 PM.
Online Users 52
Registered 1
Guests 51
Members 3364
Active Members 219
Threads 1687
Posts 7143
Top poster: Code Monkey (2203)
Welcome to our newest member, abstrakt
Most users ever online was 235, 04-11-2007 at 08:59 AM.
Speak Out! vBulletin gets the web talking!


vBulletin Setup SEO

vBulletin graphics resource images