Quote:
Originally Posted by dadu911
THERE IS A HOLE IN Latest Version: 3.6.7 PL1 ALSO!!! THEY CAN LOGIN AS ADMIN!!! MAN VBULLETIN HELP
someone logged in as admin, has changed the password and turned the forum off. He placed his url so he gets the hits.
This is SAD! Yet again another hole in VBULLETIN!
|
What hole would that be then ?
You have not offered any proof that any of the exploits of your server were via vbulletin, you've just conviently decided that a previously unknown XSS in in the events area was used, which is actually highly unlikely. It helps to actually have evidence before making wild accusations.