vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   Modification Graveyard (https://vborg.vbsupport.ru/forumdisplay.php?f=224)
-   -   [Fixed] vbPlaza (https://vborg.vbsupport.ru/showthread.php?t=144185)

Rickeo 04-07-2007 06:10 AM

Quote:

Please do cause only version info I can find in the php is this which is correct right?

define('THIS_SCRIPT', 'vbplaza');
define('VBPLAZA_RUNNING', true);
define('VBPLAZA_SCRIPT_VERSION', '1.5.8');
NOPE corect the following

Please do cause only version info I can find in the php is this which is correct right?

define('THIS_SCRIPT', 'vbplaza');
define('VBPLAZA_RUNNING', true);
define('VBPLAZA_SCRIPT_VERSION', '1.5.81');

Add a 1 to that line hope that helps :)

~Rick~

JamieLee2k 04-07-2007 09:22 AM

Rick that isn't the only thing that needs to be edited, you need to edit the vbplaza.php file and twice in the xml file, line 6 & 3304 or you can get the xml I uploaded yesterday

JamieLee2k 04-07-2007 09:26 AM

This also works for 3.6.x

Dismounted 04-07-2007 10:45 AM

Ahem...https://vborg.vbsupport.ru/showthread.php?t=144180

Bratz-Designs 04-07-2007 10:56 AM

Versions are fixed in the .php and xml file!

Matt_270581 04-07-2007 10:58 AM

Thanks Bratz-Designs!

<3 (no homo)

Hornstar 04-07-2007 01:29 PM

I'll see how this goes. thanks.

Sooner95 04-07-2007 02:03 PM

many thanks for getting a fix out for this. I know alot have been waiting.

KHALIK 04-07-2007 02:17 PM

Does this work for 3.6.5 ?

Luky 04-07-2007 02:49 PM

Well im about to install it on 3.6.5 so i bloodey hope it does! :)

Paul M 04-07-2007 03:14 PM

Quote:

Originally Posted by Redlinemotorsports (Post 1221418)
Well hopefully Bratz or the staff here will eventually let us know

I've done a code comparison on the new version compared to the removed version and it looks like the function strip_tags() has been replaced in a whole bunch of files with a vbulletin input cleaning function. I don't know if this fixes the problem as I don't have details of the original issue. I'l ask the original member of staff who dealt with this to take a look.

Edit: The staff who examined this have found that the exploits detailed to the original author have not been fixed in this version, therefore we have no alternative but to remove it again.


All times are GMT. The time now is 01:31 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01390 seconds
  • Memory Usage 1,731KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (2)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (11)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete