The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
vBulletin 3.0.7 released
It is directed primarily as a security fix that apparently is caused by enabling debug comments in templates (something production sites should not do anyway). However, it also fixes a slew of other bugs, so as usual, you should always stay up to date.
More: http://www.vbulletin.com/forum/showthread.php?t=130591 |
#2
|
||||
|
||||
|
#3
|
|||
|
|||
Hmm, I'll have a look at it.
I'm just hoping it doesn't make any major changes to the files I use for my hack, as it's almost finished now ~~. EDIT: Yes, why not create an almost entirely new attachment.php, when that's one of the most time taking parts of my hack, and I was almost done with it -.- |
#4
|
|||
|
|||
Again? Yuk.
I had just gotten 3.0.6 almost working... might as well start a fresh merge now... |
#5
|
|||
|
|||
The exploit code says 3.0.5 and up are immune. Is that not right?
|
#6
|
||||
|
||||
Quote:
|
#7
|
||||
|
||||
what is exactly the problem with using the html comments, the posts do not mention what the hole is. if it can not be discussed publically can someone drop me a pm...
|
#8
|
||||
|
||||
It wouldn't be sensible to mention how it can be exploited in public. So before anyone tries ...
|
#9
|
||||
|
||||
Quote:
|
#10
|
||||
|
||||
I understand that, but if we posted up how it can be exploted in public, then you'd have people going around exploiting people's sites. And there are LOTS of people who don't upgrade and apply patches
|
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|