View Full Version : JelSoft VBulletin Search.php Cross-Site Scripting Vulnerability
Snowball1
01-15-2010, 09:15 AM
please help! my site got suspended today by my webhost. According to my host, the search.php file in vbulletin forum was causing a problem and that I have to work on the code because someone else might be using the search.php. my host said I have used 15% mysql or something like that becasue of search.php. I have no idea. I will be very happy if you can help me. my forum is vbulletin 3.82
thanks
Lynne
01-15-2010, 02:15 PM
Do you only allow members to use the search (usergroup manager > can search forums set to no for all non-member groups)? Do you have a minimum time between searches set so it can't get hammered (vboptions > searching)? Are you using default searching for your site or did you add something?
Snowball1
01-17-2010, 10:52 AM
Do you only allow members to use the search (usergroup manager > can search forums set to no for all non-member groups)? Do you have a minimum time between searches set so it can't get hammered (vboptions > searching)? Are you using default searching for your site or did you add something?
thanks very much for your help. I was allowing unregistered users to search the forum any number of time they want but now I have disabled the searching option for unregistered users. I have set a minimum time between searches to 3mins. I am using the default searching.
vBulletin® v3.8.12 by vBS, Copyright ©2000-2025, vBulletin Solutions Inc.