View Full Version : Urgent: XSS vulnerability in RC 2, 3 & 4 - fix available!
Erwin
02-14-2004, 02:01 AM
From this announcement today by Kier at vB.com:
http://www.vbulletin.com/forum/showthread.php?t=95284
An XSS vulnerability has been discovered in vBulletin 3 and posted to BugTraq.
vBulletin 3 versions RC2, RC3 and RC4 are affected. This has necessitated the release of an updated version of includes/init.php to patch the problem.
The members' area package has been updated with this file.
If you are already running vBulletin 3 RC4, simply upload the attached init.php file to the 'includes' folder in your forum directory, overwriting the existing one.
If you are running a previous version of vBulletin 3, we recommend that you upgrade to the version of RC4 available in the members' area as soon as possible.
vBulletin 2.3.4 and earlier are not affected. Sites running vBulletin 2 need take no action.
Link to vB.com attachment: init.php (http://www.vbulletin.com/forum/attachment.php?attachmentid=8821)
__________________
Chroder
02-14-2004, 08:09 PM
Does the vulv still affect me if I don't have the external data providor features enabled? Or is that a totally different thing?
Xenon
02-14-2004, 10:04 PM
it's a totally different thing.
the external data provieder is in the file external.php but the security hole is in init.php
Chroder
02-14-2004, 10:14 PM
Can I still use the updated file if I'm using RC3? or do I have to upgrade to RC4? I'm waiting for gold before I do all my template-fixes. I don't want to do 'em twice.
Xenon
02-14-2004, 10:15 PM
you just have to compare the files and apply the xss changes.
That's what we did on vb.org :)
Chroder
02-14-2004, 10:17 PM
you just have to compare the files and apply the xss changes.
That's what we did on vb.org :)
I just uploaded it over my RC3 init.php file and everything seems to be going smoothly. I'll compare them if something starts acting up.
Thanks :)
Chroder
02-15-2004, 01:15 AM
Just a heads up that there's also a fix for search.php here (http://www.vbulletin.com/forum/showpost.php?p=612756&postcount=2)
Just a heads up that there's also a fix for search.php here (http://www.vbulletin.com/forum/showpost.php?p=612756&postcount=2)
does this update just overwrite the forums/search.php file? i just wanna make sure before i overwrite something....
Tim Wheatley
02-23-2004, 12:31 PM
does this update just overwrite the forums/search.php file? i just wanna make sure before i overwrite something....
Yeah just overwrite the init.php and search.php ones on your server with the ones made available. Note: any hacks installed within those files will need to have the code changes made again in those files.
djohn
03-13-2004, 12:22 PM
Any way to upgrade manually? I remember chaging init.php whilst installing some hack...
Xenon
03-14-2004, 11:48 AM
just compare the old init.php to the new one and add the changes to your hacked one :)
djohn
03-14-2004, 12:19 PM
Is there any special software to do this?
Xenon
03-15-2004, 01:23 PM
as mentioned on vbulletin.com
Beyond Compare by ScooterSoftware for example
NTLDR
03-18-2004, 02:12 PM
Two more files have XSS issues in them (forumdisplay.php and showthread.php). Patched versions can be found here http://www.vbulletin.com/forum/showpost.php?p=629894&postcount=4
Sebastian
03-18-2004, 03:32 PM
wow lame. every single released vb3 version has had a security patch. i left phpbb due to security holes for nothing :P
thats what happens when you use those stupid 'globalize' arrays... thanks to those that run a server with register globals.. gg.
Dean C
03-18-2004, 05:11 PM
Well the globalize does it's best to clean data - it can only do so much though. Bare in mind the gold and first main release has not been released so you installed the beta's and release candidates at your own risk :) A security audit has been done in vB3 so you should see a lot less after gold :)
Gio Takahashi
03-18-2004, 07:32 PM
wow lame. every single released vb3 version has had a security patch. i left phpbb due to security holes for nothing :P
thats what happens when you use those stupid 'globalize' arrays... thanks to those that run a server with register globals.. gg.
Well vB3 was still in its beta. ITs something that is really expected. Aftregold its rare.
Sebastian
03-18-2004, 08:10 PM
A security audit has been done in vB3 so you should see a lot less after gold :)
nice audit.. it was done a few weeks ago and they just found this hole ;)
Link14716
03-18-2004, 09:32 PM
They never said they completed the audit, now did they? ;)
Bugs will always be found, no reason to get worked up over it.
Gizmo
03-19-2004, 09:35 AM
Thanx, good to know it :p
neocorteqz
03-20-2004, 12:58 AM
Bugs will always be found, no reason to get worked up over it.
I agree. unfortunately, the whole site is down now, so looks like I have to wait till gold gets released. No big deal. :)
vBulletin® v3.8.12 by vBS, Copyright ©2000-2025, vBulletin Solutions Inc.