Go Back   vBulletin Setup > General Forums > Official vBulletin Announcements

Why not Register and remove some of the ads from vBulletin Setup
Post New Thread  Reply



#1   11-22-2006, 04:30 PM
Send a message via AIM to Brandon Send a message via MSN to Brandon Send a message via Yahoo to Brandon Brandon is a glorious beacon of lightBrandon is a glorious beacon of lightBrandon is a glorious beacon of lightBrandon is a glorious beacon of light Join Date: Jul 2006 Posts: 9,242 Location: Topeka, KS
vBulletin 3.6.4 Released


vBulletin 3.6.4

The discovery of a potential cross-site scripting (XSS) issue in the administrators control panel has necessitated the preventative release of vBulletin 3.6.4 Due to several mitigating factors, this issue is hard to exploit and careful browsing by the admins can prevent it entirely. Nonetheless, we strongly recommend that all of our customers upgrade or apply the patch as soon as possible.

Additionally, vBulletin 3.6.4 includes fixes for several non-security-related bugs, see here for a full list.

Updating your vBulletin to combat the XSS issue:

Please note that this issue is present in other versions of vBulletin as well. Please see the appropriate announcement!

You have two options to fix the XSS issue:
  1. Full Upgrade: The best way to fix the problem is to perform a full upgrade, downloading the complete 3.6.4 package from the vBulletin Members' Area and following the regular upgrade instructions.
  2. Patch: A second option is to download the patch files discussed in this thread and upload them to your web server, overwriting the existing files. The patch is available from the Members' Area patch page!
If you absolutely cannot apply the patch or upgrade...

We strongly recommend you actively take steps to address this issue. However, if this is not possible, we recommend that administrators only log into the control panel when work is necessary. While you are logged into the control panel, do not click unknown links. Log out from the control panel using the link in the upper right of the screen immediately after finishing your work. If you are unexpectedly presented with the control panel login screen after clicking a link, do not login.

PHP and MySQL Requirements

Please note that vBulletin 3.6.x requires at least PHP 4.3.3 and MySQL 4.0.16 or later
--------------------
Brandon Sheley / vBulletin Setup Staff
Check out our Newsletter for the latest vB and SEO news.
Are you looking for vBulletin work to be done on your forums ?
Would you like to Help Support vBulletin Setup.
Reply to the Welcome PM for Full Access to the Forums.. Thanks

Please do not PM me for support, that's what the forums are for.
Have you heard about Crowdgather?
Find it on Forums
Check out this cool page - Bar Code Signatures
Quote   |  
Post New Thread  Reply
vBulletin Setup > General Forums > Official vBulletin Announcements


Thread Tools
Display Modes

 
Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
vBulletin 3.6.8 Released Brandon Official vBulletin Announcements 57 12-07-2007 06:12 PM
vBulletin 3.6.7 PL 1 Released Michael Biddle vBulletin Programming & Coding 0 06-20-2007 08:14 PM
vBulletin 3.6.5 Released Brandon Official vBulletin Announcements 11 03-09-2007 12:11 PM
vBulletin 3.6.3 Released Brandon Official vBulletin Announcements 7 11-09-2006 05:18 PM
vBulletin 2.3.10 Released Brandon Official vBulletin Announcements 0 08-03-2006 10:22 PM


All times are GMT -6. The time now is 08:33 AM.

vBulletin Setup, vBulletin Setup Forums, vBulletin Services, vBulletin Blogs, vBulletin SEO, vBulletin Questions, vBulletin Skins, Styles, Templates
vBulletin Hacks / Modifications, vBulletin Monetization, Blogs, vBulletin Link Directory,Quality Link Directory