The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
||||
|
||||
Urgent: XSS vulnerability in RC 2, 3 & 4 - fix available!
From this announcement today by Kier at vB.com:
http://www.vbulletin.com/forum/showthread.php?t=95284 An XSS vulnerability has been discovered in vBulletin 3 and posted to BugTraq. vBulletin 3 versions RC2, RC3 and RC4 are affected. This has necessitated the release of an updated version of includes/init.php to patch the problem. The members' area package has been updated with this file. If you are already running vBulletin 3 RC4, simply upload the attached init.php file to the 'includes' folder in your forum directory, overwriting the existing one. If you are running a previous version of vBulletin 3, we recommend that you upgrade to the version of RC4 available in the members' area as soon as possible. vBulletin 2.3.4 and earlier are not affected. Sites running vBulletin 2 need take no action. Link to vB.com attachment: init.php __________________ |
#2
|
||||
|
||||
Does the vulv still affect me if I don't have the external data providor features enabled? Or is that a totally different thing?
|
#3
|
||||
|
||||
it's a totally different thing.
the external data provieder is in the file external.php but the security hole is in init.php |
#4
|
||||
|
||||
Can I still use the updated file if I'm using RC3? or do I have to upgrade to RC4? I'm waiting for gold before I do all my template-fixes. I don't want to do 'em twice.
|
#5
|
||||
|
||||
you just have to compare the files and apply the xss changes.
That's what we did on vb.org |
#6
|
||||
|
||||
Quote:
Thanks |
#8
|
|||
|
|||
Quote:
does this update just overwrite the forums/search.php file? i just wanna make sure before i overwrite something.... |
#9
|
||||
|
||||
Quote:
|
#10
|
|||
|
|||
Any way to upgrade manually? I remember chaging init.php whilst installing some hack...
|
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|