vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB4 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=251)
-   -   vB 4.1.4 - Vulnerable to SQL Injection? (https://vborg.vbsupport.ru/showthread.php?t=316307)

ozzy47 12-30-2014 04:57 PM

Well the main thing I can think of you may have issues with the navigation. Pre 4.2.0 did not use the Navigation Manager.

Lynne 12-30-2014 05:14 PM

Set up a test site and do an upgrade there first. Then you can modify your style, export it, and import it to the live site when you do the upgrade.

thetechgenius 12-30-2014 05:24 PM

Quote:

Originally Posted by ozzy47 (Post 2529590)
Well the main thing I can think of you may have issues with the navigation. Pre 4.2.0 did not use the Navigation Manager.

Your right. I have all my Nav Tabs coded manually in the navbar template. So when I do upgrade, I probably wont use the Navigation Manager, and just code my Nav Tabs in the navbar template. So I don't run into any issues in the long run, I think if I do it that way, it will be less of a hassle.

What do you guys/girls think?

You have to remember, it took a lot of time, money and A LOT of patience to get my forum exactly the way I want it. I custom coded a lot of the features on my forum, including a lot of the Profile, the entire Postbit Legacy, the user info bar at the top, the sticky user info bar at the top that scrolls with the page, a modified Login Menu, the javascript loading bar at the top that loads with the page, a custom ShortURL System (with another Top Level Domain), a custom coded Anonymous URL System (an updated version from the one I posted on vb.org), and MUCH MUCH more. lol

Like I said, it took a long time, a lot of work, and a lot of patience, to get my forum exactly the way I want it, without errors.

ozzy47 12-30-2014 05:46 PM

It will take some work, but you are better off in the long run. Cause all the work you have done so far is no good if someone keeps hacking the site, because you did not upgrade. :)

kh99 12-30-2014 06:15 PM

I don't remember what changes were in what version, but I know that there were some template changes made where I believe they got rid of some of the 'bit' templates and instead used a vb:each loop in the main template. But if you do as Lynne suggested then you'll see where you stand before committing to anything.

ozzy47 12-30-2014 08:18 PM

Yeah there were a few minor tweaks hear and there. But it should not be overly difficult to sort.

Paul M 12-31-2014 12:37 AM

There is at least 1 known [recent] SQL Injection in 4.1.4 (it affects all 4.x.x versions as I recall), I vaguely recall at least 1 other as well.

Its quite an old version now, and several recent patches do not go back that far.

ozzy47 12-31-2014 12:41 AM

Yeah Paul, that is what I am saying. It's time to bite the bullet and do a upgrade, especially since he is on someones radar.

thetechgenius 12-31-2014 10:46 AM

I agree. I will do as Lynne suggested and install a backup of my forum on a Sub-Domain, and Password Protect the directory since its only for testing purposes. This way I can upgrade to the latest version of vB to see what I need to change in the style, without it affecting my Live Board if anything goes wrong.

Thank You Paul, Ozzy, Lynne and everyone else!! Its greatly appreciated!

ozzy47 12-31-2014 10:50 AM

Not a problem, let us know how it goes. :)


All times are GMT. The time now is 05:34 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01106 seconds
  • Memory Usage 1,730KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete