Go Back   vBulletin Modification Discussions > Site Business > News and Announcements > Jelsoft vBulletin Announcements
Home Register FAQ Members List Calendar Mark Forums Read
vBSEO Info Tags

Reply
 
LinkBack Thread Tools
Old 07-07-2008, 09:51 AM   #1 (permalink)
Administrator
 
Code Monkey's Avatar
 
Join Date: May 2006
Posts: 2,238
Code Monkey is on a distinguished road
iTrader: (0)
Post vBulletin 3.7.2 PL1 and 3.6.10 PL3 Released

vBulletin 3.7.2 PL1 / vBulletin 3.6.10 PL3



An XSS flaw affecting the vBulletin control panel logging system has been identified, another was found affecting boards running in debug mode. It could allow an attacker to trick an admin into unwittingly performing an action within the control panel that they had not intended. To resolve this issue, it is necessary to release patch level versions of vBulletin 3.7.2 and 3.6.10.



One of the XSS flaws was discovered by Jessica Hope and the other by ourselves.



The upgrade process is the same as previous patch level releases - simply download the patch from the Members Area, extract the files and upload to your webserver, overwriting the existing files. There is no upgrade script required.



As with all security-based releases, we recommend that all customers upgrade as soon as possible in order to prevent any potential damage resulting from the flaw being exploited.





Upgrading from 3.7.2, 3.6.10 or their patch level versions



If you are already running 3.7.2, 3.6.10 or their patch level versions, the process you will be required to follow to make your board immune to the XSS problem is very simple.



There is no need to run an upgrade script if you are already running 3.7.2, 3.6.10 or their patch level versions.



Visit the Patches section of the vBulletin Members' Area and download either the patch for 3.7.2, or the patch for 3.6.10, according to the version you are currently running, then extract the files from the archive you downloaded, then upload the files to your board via FTP etc., overwriting the existing files. This will update your version to the PL1 or PL3 release respectively.



The 3.6.10 PL3 patch file also includes the PL1 and PL2 fixes.





Upgrading from Versions Earlier than 3.7.2 or 3.6.10



If you are not already running 3.7.2 or 3.6.10, you should download the most latest version from the Members' Area and perform an upgrade as normal.



Full instructions for upgrading vBulletin are available here.





Download vBulletin 3.7.2 PL1 or 3.6.10 PL3



As usual, both versions released today are available for all customers with valid, active licenses to download from the vBulletin Members' Area.



vBulletin Members Area





Link To Original Article

__________________
Please do not PM me unless it's personal. General vBulletin or mod questions by PM will be ignored.

Try the vBSEO Demo

Click here for Instant Community
Code Monkey is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links

Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On


A vBSkinworks Design Recoded By vBModder.
All Code Distributed On This Site is © 2006 by it's author.
Search Engine Optimization by vBSEO 3.1.0

All times are GMT -7. The time now is 12:53 AM.
Online Users 31
Registered 1
Guests 30
Members 3924
Active Members 159
Threads 1857
Posts 7348
Top poster: Code Monkey (2238)
Welcome to our newest member, nizmo
Most users ever online was 235, 04-11-2007 at 09:59 AM.
Speak Out! vBulletin gets the web talking!


vBulletin Setup SEO

vBulletin graphics resource images