vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB4 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=251)
-   -   Our webhost will block the site because of vulnerability in CKEditor 3.6.2 (https://vborg.vbsupport.ru/showthread.php?t=294366)

Markowitch 01-25-2013 08:21 AM

Our webhost will block the site because of vulnerability in CKEditor 3.6.2
 
Hey. I just borrow my son's account to ask about security issue.

Our webhost - Domeneshop.no in Norway - believe that we have a security problem on the forum. When we asked what the problem is, we have received the following information about the cause of the alleged vulnerability:
CKEditor 3.6.2 ./www/clientscript/ckeditor/
vBulletin 4.2.0 ./www/
.... without other comments.

We are running vBulletin 4.2.0 Patch Level 3

What's going on?. If there is a security issue as our web host said - we have not heard about it, even from other vBulletin forums, we work with.

Is it a security problem with CKEditor 3.6.2 as our web host says, and if so, how to solve this?

I've only heard of this particular problem in Drupal, Jomla etc. but not in vBulletin. I'm really lost.

Thank you in advance for answers

DeMiNe0 01-29-2013 04:18 PM

It is an issue with vbulletin. vbulltin uses an older version of ckeditor. There is a bug report open about the issues here. It's been open for about 6 months now, but it doesn't appear that vbulletin is planning on fixing it ATM. Your best bet is to switch hosts.

http://tracker.vbulletin.com/browse/VBIV-13267

SRobbins1977 01-29-2013 04:37 PM

Quote:

Originally Posted by DeMiNe0 (Post 2400307)
It is an issue with vbulletin. vbulltin uses an older version of ckeditor. There is a bug report open about the issues here. It's been open for about 6 months now, but it doesn't appear that vbulletin is planning on fixing it ATM. Your best bet is to switch hosts.

http://tracker.vbulletin.com/browse/VBIV-13267

How is that a security vulnerability issue? ...that's more of a quality issue. I would switch providers that providers security team has a few rocks loose.


All times are GMT. The time now is 06:53 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01886 seconds
  • Memory Usage 1,714KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (3)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete