Log in

View Full Version : vBulletin 3.6.3, 3.5.6, 3.0.16 & 2.3.11 Released


Paul M
11-08-2006, 06:00 PM
An undocumented behaviour in all Windows versions of Internet Explorer has rendered vBulletin vulnerable to a potential cross-site scripting flaw (XSS).

Therefore, Jelsoft have decided to put out a preventative security releases in order to work-around the Internet Explorer problem before it is exploited.

The official announcement threads for these releases can be found here.

vB 3.6.3 (http://www.vbulletin.com/forum/showthread.php?t=207860)
vB 3.5.6 (http://www.vbulletin.com/forum/showthread.php?t=207859)
vB 3.0.16 (http://www.vbulletin.com/forum/showthread.php?t=207858)
vB 2.3.11 (http://www.vbulletin.com/forum/showthread.php?t=207857)

In addition, vB 3.6.3 also includes fixes for approximately 50 bugs that were discovered in 3.6.2. For this reason, Jelsoft recommend all customers upgrade to 3.6.3 as soon as possible.

da420
11-08-2006, 06:05 PM
Cool, thanks for the update Paul.

Ziki
11-08-2006, 06:10 PM
Will patch! :D

Mudvayne
11-08-2006, 06:29 PM
I've allready upgraded my forum :D..

projectego
11-08-2006, 07:23 PM
* projectego upgrades to 3.6.3 ;)

Shazz
11-08-2006, 09:33 PM
*Patched...
I don't want to get another headache on another upgrade....
They come out soo SOON

Spiffware
11-08-2006, 11:06 PM
did they change vars too will the 3.6.2 hacks work?

afx1
11-08-2006, 11:19 PM
did they change vars too will the 3.6.2 hacks work?

3.6.2 hacks still work.

evenmonkeys
11-09-2006, 07:44 AM
Add the 3.6.3 to the list of modification versions!!! =P

Just upgraded my forums. I forgot how nice the upgrades were when you didn't skip fifty of em. Haha.

Spiffware
11-09-2006, 11:15 AM
3.6.2 hacks still work.
thank you then i guess ill upgrade this week.

Shazz
11-09-2006, 11:18 AM
Add the 3.6.3 to the list of modification versions!!! =P

Just upgraded my forums. I forgot how nice the upgrades were when you didn't skip fifty of em. Haha.
All 3.6.2 Mods work..

untold4you
11-09-2006, 04:42 PM
Can someone tell me why there isen't a patch for version 3.6.0 ?

Tnx!

The Itchy One
11-09-2006, 06:38 PM
download the 3.6.3 full file to your domain and run the upgrade_360.php file

Andrew
11-09-2006, 07:07 PM
I'm so glad this came out now - My download and support period expires again tomorrow :p Was an easy upgrade too, as there were minimal template changes coming from 3.6.2.

evenmonkeys
11-09-2006, 08:10 PM
All 3.6.2 Mods work..
I know...

andrewrhs
11-11-2006, 03:15 PM
upgraded, works perfectly :D

Phaedrus
11-12-2006, 04:05 AM
Worked well for me. Very few template changes, easy to rework... Let's hope this one lasts for a bit. This gets tiring!

Shazz
11-12-2006, 04:09 AM
Worked well for me. Very few template changes, easy to rework... Let's hope this one lasts for a bit. This gets tiring!
$50 they will come up with something (3.6.4) before Jan.
Its a big vB team, and they could re-work something like a vB 10.0

Phaedrus
11-12-2006, 04:21 AM
$50 they will come up with something (3.6.4) before Jan.
Its a big vB team, and they could re-work something like a vB 10.0

No bet... What do you take me for? :tired:

Shazz
11-12-2006, 04:35 AM
What Do I take you for?

evenmonkeys
11-12-2006, 04:52 AM
$50 they will come up with something (3.6.4) before Jan.
Its a big vB team, and they could re-work something like a vB 10.0
And what's wrong with that? There's absolutely no way to cover every single flaw and security hole indefinitely. That's what a majority of the updates vBulletin sends out are. When someone reports a security issue, vBulletin has no other choice but to send out a repair for it. Would you rather they not do anything about it and let people's forum be hacked to pieces? I think not.

They do a damn good job keeping the best forum software available up to date and nearly flawless in comparison. It's not fair to criticize them. They do as much as they can with what information they have.

Shazz
11-12-2006, 04:55 AM
And what's wrong with that? There's absolutely no way to cover every single flaw and security hole indefinitely. That's what a majority of the updates vBulletin sends out are. When someone reports a security issue, vBulletin has no other choice but to send out a repair for it. Would you rather they not do anything about it and let people's forum be hacked to pieces? I think not.

They do a damn good job keeping the best forum software available up to date and nearly flawless in comparison. It's not fair to criticize them. They do as much as they can with what information they have.
I wasen't critizing, i was responding to a comment that they will have one out soon again as well
Yes they do a good job... Forgot this forum is Really Serious talk

Ziki
11-12-2006, 04:41 PM
I have a scanner which found two other security holes in vb but that darn thing doesn't display them until I buy it :D

Shazz
11-12-2006, 04:41 PM
I have a scanner which found two other security holes in vb but that darn thing doesn't display them until I buy it :D
Link to what scanner your talking about?