vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   Official vB.com Announcements (https://vborg.vbsupport.ru/forumdisplay.php?f=240)
-   -   Reported 4.0.2 PL1 XSS Vunerability (https://vborg.vbsupport.ru/showthread.php?t=238779)

vB.Org System 03-21-2010 05:20 PM

Reported 4.0.2 PL1 XSS Vunerability
 
Regarding this reported exploit: http://inj3ct0r.com/exploits/9697

An official patch is forthcoming. Meanwhile I have attached a patched type.php file to this message. Unzip that file and upload it, replacing the existing ../vb/search/type.php file

Note: This is for those running 4.0.2 PL1 only.

If for some reason you want to apply this patch yourself, find the following file:

../vb/search/type.php

In that type.php file, find this near the bottom of the file:

'query' => TYPE_STR,

Replace that with this:

'query' => TYPE_NOHTML,

Please note that if you have already applied Paul M's path here, then you do not have to apply this patch.
Attached Files


More...


All times are GMT. The time now is 07:21 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01119 seconds
  • Memory Usage 1,707KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (1)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete