Quote:
Originally Posted by Marco van Herwaarden
If you have information regarding vulnerabilities in the default vBulletin software, then please address this in a support ticket.
Posting on the forums "there is everywhere a big security risk in the vb-script" does not get anything solved if there is a real issue (which i doubt), it only will make others nervous for no reason.
|
Exactly the same happened to me before! When I was using vb latest version 3.7.3 ( in that time ) just I was told to open ticket ... The vb support and vbulletin moderators insist on " There is no security bug on vBulletin default !! "
After that I found the security
bug and report it .....Now I see the same sentences as above ...
One more thing vbulletin.com/org never used 3.7.2 or 3.7.3 ..3.7.5 versions !
Quote:
Originally Posted by Paul M
Hmm, you're right, I just looked ....
Dont understand why either of those is needed myself, surely all you need is the client id.
Oh well. Not something I will be using anyway, so it doesnt really matter to me. 
|
Please take a look at this matter . Collecting your customer private data because of new features on 3.8 version make the customers confidence on vBulletin weak ...
Thinking about this tow thing ( denying the bugs + asking unnecessary data ) is not good for us as customers...