Yes the wonderful world of vbulletin.org. quarantine your work and then leave you in no mans land in regards to your ability to deal with your installee's. the quarantine system is **** but the powers that be aren't interested in my opinion regarding the matter.
anyway there was apparently a potential XSS exploit in the group creation process. to be honest that's as much info as i was given. the exploit was fixed by cleaning the data with NOHTML types. the only file that was changed for the index.php and also viewthread.php to remove the array_merge error.
|