Brad
01-04-2006, 05:57 PM
A XSS (cross-site scripting) flaw has been discovered in all three branches of vBulletin, it's recommended that you upgrade your installation to the latest version.
vBulletin.com Announcement threads
vB 2.3.9: http://www.vbulletin.com/forum/showthread.php?t=170001
vB 3.0.12: http://www.vbulletin.com/forum/showthread.php?t=169999
vB 3.5.3: http://www.vbulletin.com/forum/showthread.php?t=169997
Upgrading vBulletin
Follow the instructions found here (http://www.vbulletin.com/docs/html/upgrade)
Patch vBulletin
If you do not want to run the full upgrade at this time you should at least patch your installation. You can do this by using the files found below.
vB 2.3.9: Patch files (http://www.vbulletin.com/forum/showpost.php?p=1046307&postcount=2)
vB 3.0.12: Patch files (http://www.vbulletin.com/forum/showpost.php?p=1046299&postcount=2)
vB 3.5.3: Patch files (http://www.vbulletin.com/forum/showpost.php?p=1046292&postcount=2)
vB 3.5.x can also be patched with the plug-in system, click here (http://www.vbulletin.com/forum/showpost.php?p=1046293&postcount=3) for details.
Changed files/templates
A list of changed files/templates in the new version(s), this is helpful if you have made modifications to the source code or templates.
vB 2.3.9: list of changed files (http://www.vbulletin.com/forum/showpost.php?p=1046341&postcount=4), No template changes.
vB 3.0.12: list of changed files (http://www.vbulletin.com/forum/showpost.php?p=1046343&postcount=4), No template changes.
vB 3.5.3: list of changed files (http://www.vbulletin.com/forum/showpost.php?p=1046351&postcount=5), list of changed templates (http://www.vbulletin.com/forum/showpost.php?p=1046297&postcount=4).
Other bug fixes
vB 2.3.9: None
vB 3.0.12: None
vB 3.5.3: List of fixed bugs (http://www.vbulletin.com/forum/bugs35.php?do=list&s=&textsearch=&bugtypeid=0&status=20&severity=0&vbversion=3.5.2&assignid=0&sortby=lastreply&sortdir=desc).
vBulletin.com Announcement threads
vB 2.3.9: http://www.vbulletin.com/forum/showthread.php?t=170001
vB 3.0.12: http://www.vbulletin.com/forum/showthread.php?t=169999
vB 3.5.3: http://www.vbulletin.com/forum/showthread.php?t=169997
Upgrading vBulletin
Follow the instructions found here (http://www.vbulletin.com/docs/html/upgrade)
Patch vBulletin
If you do not want to run the full upgrade at this time you should at least patch your installation. You can do this by using the files found below.
vB 2.3.9: Patch files (http://www.vbulletin.com/forum/showpost.php?p=1046307&postcount=2)
vB 3.0.12: Patch files (http://www.vbulletin.com/forum/showpost.php?p=1046299&postcount=2)
vB 3.5.3: Patch files (http://www.vbulletin.com/forum/showpost.php?p=1046292&postcount=2)
vB 3.5.x can also be patched with the plug-in system, click here (http://www.vbulletin.com/forum/showpost.php?p=1046293&postcount=3) for details.
Changed files/templates
A list of changed files/templates in the new version(s), this is helpful if you have made modifications to the source code or templates.
vB 2.3.9: list of changed files (http://www.vbulletin.com/forum/showpost.php?p=1046341&postcount=4), No template changes.
vB 3.0.12: list of changed files (http://www.vbulletin.com/forum/showpost.php?p=1046343&postcount=4), No template changes.
vB 3.5.3: list of changed files (http://www.vbulletin.com/forum/showpost.php?p=1046351&postcount=5), list of changed templates (http://www.vbulletin.com/forum/showpost.php?p=1046297&postcount=4).
Other bug fixes
vB 2.3.9: None
vB 3.0.12: None
vB 3.5.3: List of fixed bugs (http://www.vbulletin.com/forum/bugs35.php?do=list&s=&textsearch=&bugtypeid=0&status=20&severity=0&vbversion=3.5.2&assignid=0&sortby=lastreply&sortdir=desc).