Go Back   vBulletin Setup > General Forums > Official vBulletin Announcements

Reply 
 
LinkBack Thread Tools Display Modes
Old 07-07-2008, 01:50 PM   #1
Community Manager
Supporters
vBulletin Owner
vBSetup Mods
 
Brandon Sheley's Avatar
 
Join Date: Jul 2006
Location: Topeka, KS
Posts: 14,114
Blog Entries: 35
Brandon Sheley is a splendid one to beholdBrandon Sheley is a splendid one to beholdBrandon Sheley is a splendid one to beholdBrandon Sheley is a splendid one to beholdBrandon Sheley is a splendid one to beholdBrandon Sheley is a splendid one to behold
Send a message via AIM to Brandon Sheley Send a message via MSN to Brandon Sheley Send a message via Yahoo to Brandon Sheley
vBulletin 3.7.2 PL1 / vBulletin 3.6.10 PL3

An XSS flaw affecting the vBulletin control panel logging system has been identified, another was found affecting boards running in debug mode. It could allow an attacker to trick an admin into unwittingly performing an action within the control panel that they had not intended. To resolve this issue, it is necessary to release patch level versions of vBulletin 3.7.2 and 3.6.10.

One of the XSS flaws was discovered by Jessica Hope and the other by ourselves.

The upgrade process is the same as previous patch level releases - simply download the patch from the Members Area, extract the files and upload to your webserver, overwriting the existing files. There is no upgrade script required.

As with all security-based releases, we recommend that all customers upgrade as soon as possible in order to prevent any potential damage resulting from the flaw being exploited.


Upgrading from 3.7.2, 3.6.10 or their patch level versions

If you are already running 3.7.2, 3.6.10 or their patch level versions, the process you will be required to follow to make your board immune to the XSS problem is very simple.

There is no need to run an upgrade script if you are already running 3.7.2, 3.6.10 or their patch level versions.

Visit the Patches section of the vBulletin Members' Area and download either the patch for 3.7.2, or the patch for 3.6.10, according to the version you are currently running, then extract the files from the archive you downloaded, then upload the files to your board via FTP etc., overwriting the existing files. This will update your version to the PL1 or PL3 release respectively.

The 3.6.10 PL3 patch file also includes the PL1 and PL2 fixes.


Upgrading from Versions Earlier than 3.7.2 or 3.6.10

If you are not already running 3.7.2 or 3.6.10, you should download the most latest version from the Members' Area and perform an upgrade as normal.

Full instructions for upgrading vBulletin are available here.


Download vBulletin 3.7.2 PL1 or 3.6.10 PL3

As usual, both versions released today are available for all customers with valid, active licenses to download from the vBulletin Members' Area.

vBulletin Members Area


More...
__________________
Brandon Sheley / vBulletinSetup Staff
Check the Newsletter & Marketplace for the latest deals.
Looking for a place to Support vBulletinSetup?
Submit your Forum and other Quality Websites.


Brandon Sheley is offline   Reply With Quote

Advertisement [Remove Advertisement]

Old 07-07-2008, 02:42 PM   #2
vBulletin Owner
 
Yogesh Sarkar's Avatar
 
Join Date: Feb 2007
Location: New Delhi, India
Posts: 908
Blog Entries: 1
Yogesh Sarkar is just really niceYogesh Sarkar is just really niceYogesh Sarkar is just really nice
Re: vBulletin 3.7.2 PL1 / vBulletin 3.6.10 PL3

Just updated
Yogesh Sarkar is offline   Reply With Quote
Old 07-07-2008, 07:57 PM   #3
vBulletin Owner
 
Magnumutz's Avatar
 
Join Date: Dec 2006
Location: Romania
Posts: 584
Magnumutz is a jewel in the rough
Send a message via MSN to Magnumutz Send a message via Yahoo to Magnumutz Send a message via Skype™ to Magnumutz
Re: vBulletin 3.7.2 PL1 / vBulletin 3.6.10 PL3

Me too.
__________________
rapidshare downloads
Magnumutz is offline   Reply With Quote
Old 07-16-2008, 02:59 AM   #4
Supporters
vBulletin Owner
 
Caddyman's Avatar
 
Join Date: Dec 2006
Location: Delaware
Posts: 4,035
Blog Entries: 1
Caddyman has much to be proud ofCaddyman has much to be proud ofCaddyman has much to be proud ofCaddyman has much to be proud ofCaddyman has much to be proud ofCaddyman has much to be proud of
Send a message via AIM to Caddyman Send a message via MSN to Caddyman Send a message via Yahoo to Caddyman Send a message via Skype™ to Caddyman
Re: vBulletin 3.7.2 PL1 / vBulletin 3.6.10 PL3

YAYAYAY more upgrades!!!

i always hold off a bit...
__________________
Delaware Online
Caddyman is offline   Reply With Quote
Reply 
vBulletin Setup > General Forums > Official vBulletin Announcements

Tags
download vbulletin, pl1, pl3, vbulleitn released, vbulletin

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Important Who we use for vBulletin hosting (the best vbulletin host) Brandon Sheley vBulletin Setup Announcements 0 10-03-2009 04:06 PM
vBulletin 4.0 is going to cost even more? (vBulletin Leaked) Brandon Sheley Official vBulletin Announcements 342 09-04-2009 12:13 PM
Make Money Help us promote your vBulletin Services | vBulletin Support | vBulletin Help Brandon Sheley vBulletin Services 0 08-25-2009 08:44 AM
vBulletin Blog Running on vBulletin.com Brandon Sheley Official vBulletin Announcements 9 01-22-2008 05:50 PM
How long have you been using vBulletin and how many vBulletin licenses do you own? Brent Troubleshooting vBulletin Problems 15 11-29-2006 09:04 PM


All times are GMT -8. The time now is 09:38 AM.