The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
||||
|
||||
Potential XSS in vBulletin 3.0.7 and older
Posted at vBulletin.com by Kier:
http://www.vbulletin.com/forum/showthread.php?t=133459 -------------------------------------------------------------------------- It has come to our attention that an XSS issue exists within vBulletin 3 in versions up to and including 3.0.7. However, the circumstances that allow this XSS issue to be exploited are rare so the vast majority of installations will be unaffected. Your installation is vulnerable if
Both of these settings can be found in vBulletin Options > Message Searching Options (Default Search) If you are unable to change these settings, you can simply overwrite the existing includes/functions_search.php file with the one attached to this thread. If neither of these conditions applies to you, there is no need to download this file at all. Attached Filesfunctions_search.php (21.9 KB, 177 |
#2
|
|||
|
|||
hi,
patch downloaded & my vbulletin installation patched thanks jelsoft ... |
#3
|
||||
|
||||
what about installations that have the full text searching hack installed ?
|
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|