03-25-2004, 02:12 AM
vBulletin 2.3.5 is a security and bug fix release. If you are running vBulletin 2.3.4 or older, we recommend you upgrade to 2.3.5 or 3.0.0 as soon as possible; if this is not possible, you can simply use the updated memberlist.php and forumdisplay.php from this version to obtain the security fix.
vBulletin 3 is not affected by the problems fixed in this release.
The bugs fixed include:
* XSS issues in memberlist.php and forumdisplay.php.
* Form in modifycoppa template pointing to member.php to register.php.
* Changed default value for Netscape Navigator 6 text area columns to 60.
* Fixed a bug where access masks were not accounted for in forum jump on forumdisplay.php.
* Quoted filenames in content-disposition headers in attachment.php and avatar.php.
More info (
vBulletin 3 is not affected by the problems fixed in this release.
The bugs fixed include:
* XSS issues in memberlist.php and forumdisplay.php.
* Form in modifycoppa template pointing to member.php to register.php.
* Changed default value for Netscape Navigator 6 text area columns to 60.
* Fixed a bug where access masks were not accounted for in forum jump on forumdisplay.php.
* Quoted filenames in content-disposition headers in attachment.php and avatar.php.
More info (