vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   Official vB.com Announcements (https://vborg.vbsupport.ru/forumdisplay.php?f=240)
-   -   Security Exploit fixed in vBulletin 4.2.2 and 4.2.3. (https://vborg.vbsupport.ru/showthread.php?t=315042)

vB.Org System 10-24-2014 06:21 PM

Security Exploit fixed in vBulletin 4.2.2 and 4.2.3.
 
A security issue has been reported to us that affects vBulletin 4. We have released new builds of vBulletin 4.2.2 and 4.2.3 to account for this vulnerability. The issue may allow attackers to access sensitive data via the mobile API. It is recommended that all users update as soon as possible. If you're using a version of vBulletin 4 older than 4.2.2, it is recommended that you upgrade to that version as soon as possible.

You can download the build for your version here: http://members.vbulletin.com/

Special thanks to NytroRST for reporting this issue.

To install the new build, download your version of vBulletin 4 (4.2.2 or 4.2.3) then upload all files found within the zip file except the /install/ directory. Make sure to overwrite the existing files on your server.

If you're using a version prior to 4.2.2, then you should follow standard upgrade procedures.

Builds available:
vBulletin 4.2.2 Patch Level 2
vBulletin 4.2.3 Beta 1


All times are GMT. The time now is 04:31 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.00956 seconds
  • Memory Usage 1,704KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (1)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete