Welcome to Egypt Forums Mark forums read | Egypt Main Page
Egypt Forums
Arabic Movies



Articles Thread, vBulletin 3.7.4 PL1 Released in vBulletin; vBulletin 3.7.4 PL1 Released An XSS flaw within the user control panel has recently been discovered. This could allow an ...

Short Link: http://forum.egypt.com/enforum/showthread.php?t=6612


Reply
LinkBack Thread Tools Display Modes
vBulletin 3.7.4 PL1 Released
 
 
The God Father
Developer's Avatar

Reply With Quote
 
Join Date: Jul 2008
Location: NDC
Posts: 5,425
23-11-2008, 09:48 PM
 
vBulletin 3.7.4 PL1 Released

An XSS flaw within the user control panel has recently been discovered. This could allow an attacker to carry out an action as a user or obtain access to a user's account. To resolve this issue, it is necessary to release a patch level version of vBulletin 3.7.4.

vBulletin 3.6 is not affected. vBulletin 3.8 is affected, and the next beta/release candidate will include the fix.

The upgrade process is the same as previous patch level releases - simply download the patch from the Members Area, extract the files and upload to your webserver, overwriting the existing files. There is no upgrade script required.

As with all security-based releases, we recommend that all customers upgrade as soon as possible in order to prevent any potential damage resulting from the flaw being exploited.


Upgrading from 3.7.4

If you are already running 3.7.4, the process you will be required to follow to make your board immune to this flaw is very simple.

There is no need to run an upgrade script if you are already running 3.7.4.

Visit the Patches section of the vBulletin Members' Area and download the patch for 3.7.4, then extract the files from the archive you downloaded, then upload the files to your board via FTP etc., overwriting the existing files. This will update your version to the PL1 release.


Upgrading from Versions Earlier than 3.7.4

If you are not already running 3.7.4, you should download the latest version from the Members' Area and perform an upgrade as normal.

Full instructions for upgrading vBulletin are available here.


Download vBulletin 3.7.4 PL1

As usual, the version released today is available for all customers with valid, active licenses to download from the vBulletin Members' Area.

vBulletin Members Area




You can discuss this patch release in the existing 3.7.4 release discussion.
__________________
I Love Walking In The Rain Cuz Nobody Know I'm Crying !!
 
 
 
Reply

Articles Thread, vBulletin 3.7.4 PL1 Released in vBulletin; vBulletin 3.7.4 PL1 Released An XSS flaw within the user control panel has recently been discovered. This could allow an ...

Short Link: http://forum.egypt.com/enforum/showthread.php?t=6612


Bookmarks

Tags
pl1, released, vbulletin


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
What is VBulletin! - Tags: VBulletin / Forums / PHP / Script /Community / Programming SABRAWY Articles 23 29-05-2009 12:28 PM
[RS.com] The NEW pogo autoloader released 2-24-08 Developer Software and Programs 0 08-12-2008 06:30 PM
vBulletin 3.7.2 PL1 and 3.6.10 PL3 Released Developer Articles 0 02-11-2008 05:44 AM
µTorrent 1.8.1 released Developer Software and Programs 0 07-10-2008 01:56 PM
vBulletin 3.7.3 PL1 and 3.6.11 PL1 Released Developer Articles 0 10-09-2008 06:28 PM