Go Back   vBulletin Modification Discussions > Site Business > News and Announcements > Jelsoft vBulletin Announcements
Home Register FAQ Members List Calendar Mark Forums Read
vBSEO Info Tags

Reply
 
LinkBack Thread Tools
Old 04-23-2008, 10:51 AM   #1 (permalink)
Administrator
 
Code Monkey's Avatar
 
Join Date: May 2006
Posts: 2,193
Code Monkey is on a distinguished road
iTrader: (0)
Post vBulletin 3.6.10 Released

vBulletin 3.6.10



Although 3.6.9 was intended to be the final maintenance release for the 3.6.x series, the discovery of a CSRF (cross-site request forgery) vulnerability in vBulletin over the weekend has forced the release of an update to plug the hole.



The CSRF problem potentially enabled an administrator who had been lured to a third-party site to unknowingly submit forms located on the forum he or she administers, resulting in potential damage to the forum. Actions performed via the Admin Control Panel are not vulnerable.



The fix for the CSRF issue involves many files and many templates, so unfortunately it is not feasible to produce a patch or a plugin to address the problem. Only a full-scale update will work.



We recommend that customers running versions of vBulletin older than 3.6.10 upgrade as soon as possible.



Template Changes Automatically Applied



With one exception (userinfraction_view), all the template changes in this release require a revert, but they are simple to apply so the upgrade script will attempt to do this for you. The list below shows which templates will be affected by the change, and how they will be altered. Customized templates will be automatically updated, but your customized changes will be retained.





Upgrading from Previous Versions



3.6.10 is a security release and we recommend that all customers upgrade to benefit from many bug fixes and stability improvements.



Full instructions for upgrading vBulletin are available here.



PHP and MySQL Requirements



Please note that vBulletin 3.6.x requires at least PHP 4.3.3 and MySQL 4.0.16 or later.



However, we recommend that vBulletin 3.6.x is run on PHP 5.2.5 with APC (or a similar opcode cache) and MySQL 5.0.51 for best performance and stability.



End of Life for PHP 4



The PHP group has announced the end of life for PHP 4. We strongly recommend that customers update their servers to PHP 5.2.5 if they are still running PHP 4. vBulletin 3.6.10 supports PHP 5 without any problems, though you may need to disable strict mode for MySQL, see here on how to enable 'force_sql_mode'.



Note: We will continue to support PHP 4 in the vBulletin 3 series.



Download vBulletin 3.6.10



As usual, vBulletin 3.6.10 is available for all customers with valid, active licenses to download from the vBulletin Members' Area.



vBulletin Members Area





Link To Original Article

__________________
Please do not PM me unless it's personal. General vBulletin or mod questions by PM will be ignored.

Try the vBSEO Demo

Click here for Instant Community
Code Monkey is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links

Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On


A vBSkinworks Design Recoded By vBModder.
All Code Distributed On This Site is © 2006 by it's author.
Search Engine Optimization by vBSEO 3.1.0

All times are GMT -7. The time now is 09:49 PM.
Online Users 61
Registered 1
Guests 60
Members 3144
Active Members 227
Threads 1575
Posts 6982
Top poster: Code Monkey (2193)
Welcome to our newest member, VbGuru
Most users ever online was 235, 04-11-2007 at 08:59 AM.
Speak Out! vBulletin gets the web talking!


vBulletin Setup SEO

vBulletin graphics resource images