![]() |
vB 3.0.8 released!
Read here:
http://www.vbulletin.com/forum/showthread.php?t=148584 Main changes: 1. MySQL 4.1 Support added. 2. XSS Flaws in faq.php, private.php, and several templates fixed. To manually patch your vB 3.0.7 to fix the file security issues 3.0.8: In private.php, find: PHP Code:
PHP Code:
PHP Code:
PHP Code:
Then to fix the template IE XSS problem, in all your templates where you see: HTML Code:
<title> HTML Code:
$headinclude |
Nice to see a new version on the 3.0.x series.
|
Hmm didn't 2.x have the same issues with MySQL?
|
Bump - added to the first post the security file and template changes needed. ;)
|
Quote:
where's the install button? :D Quote:
|
Maybe with a SQL-Replace directly in the database.
|
I love vB search :)
http://www.vbulletin.com/forum/showthread.php?t=143320 As mySQL also supports regex, it might also be possible to do this directly in the DB. But mySQL Regex is not PCRE compatible, eg. different Syntax. |
So it's just a security release?
|
Quote:
|
Quote:
|
All times are GMT. The time now is 01:44 PM. |
Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|