The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
||||
|
||||
vB 3.0.8 released!
Read here:
http://www.vbulletin.com/forum/showthread.php?t=148584 Main changes: 1. MySQL 4.1 Support added. 2. XSS Flaws in faq.php, private.php, and several templates fixed. To manually patch your vB 3.0.7 to fix the file security issues 3.0.8: In private.php, find: PHP Code:
PHP Code:
PHP Code:
PHP Code:
Then to fix the template IE XSS problem, in all your templates where you see: HTML Code:
<title>
HTML Code:
$headinclude |
#2
|
||||
|
||||
Nice to see a new version on the 3.0.x series.
|
#3
|
|||
|
|||
Hmm didn't 2.x have the same issues with MySQL?
|
#4
|
||||
|
||||
Bump - added to the first post the security file and template changes needed.
|
#5
|
||||
|
||||
Quote:
where's the install button? Quote:
|
#6
|
|||
|
|||
Maybe with a SQL-Replace directly in the database.
|
#7
|
||||
|
||||
I love vB search
http://www.vbulletin.com/forum/showthread.php?t=143320 As mySQL also supports regex, it might also be possible to do this directly in the DB. But mySQL Regex is not PCRE compatible, eg. different Syntax. |
#8
|
||||
|
||||
So it's just a security release?
|
#9
|
|||
|
|||
Quote:
|
#10
|
||||
|
||||
Quote:
|
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|