กรุณาปิด โปรแกรมบล๊อกโฆษณา เพราะเราอยู่ได้ด้วยโฆษณาที่ท่านเห็น
Please close the adblock program. Because we can live with the ads you see


thxf.org

news Potential vBSEO vulnerability

Dear VB License Holder,

It has come to our attention that there may be a potential security vulnerability in VBSEO affecting the latest version of the software (and potentially other versions as well). We've attempted to contact the vendor, but as they have been non-responsive we felt we should alert the community as many of our customers use this add-on software.

If you think you might be running a vulnerable version of the software, there is a simple fix: just comment out the following lines in the file vbseo/includes/functions_vbseo_hook.php:

Code:
if(isset($_REQUEST['ajax']) && isset($_SERVER['HTTP_REFERER']))
$permalinkurl = $_SERVER['HTTP_REFERER'].$permalinkurl;
should be changed to:
Code:
// if(isset($_REQUEST['ajax']) && isset($_SERVER['HTTP_REFERER']))
// $permalinkurl = $_SERVER['HTTP_REFERER'].$permalinkurl;
If you are running the "Suspect File Versions" diagnostics tool, you will additionally need to generate a new MD5 sum of the above file and edit upload/includes/md5_sums_crawlability_vbseo.php to use the new MD5 sum on the line:

'functions_vbseo_hook.php' => 'NEW MD5 SUM GOES HERE',

Please be aware that you are making these changes at your own risk. We don't know if making this change affects the terms of your VBSEO license and we can't be responsible if making this change breaks your site.

CVE-2014-9463 has been assigned to this potential vulnerability by cve.mitre.org.
 


Similar threads

  • Article Article
vBulletin 6.1.2 Changes and Updates vBulletin 6.1.2 is available for download. vBulletin Cloud upgrades will begin in within 7-14 days. Gallery Channels Gallery Channels are a new top-level...
Replies
0
Views
94
thxf.org 
  • Article Article
vBulletin 6.1.1 Changes and Updates vBulletin 6.1.1 is now available to download. In the upcoming weeks, vBulletin Cloud customers will be automatically upgraded to the new version. Front End...
Replies
1
Views
459
thxf.org 
  • Article Article
vBulletin 6.1.0 Changes and Updates A preview release of vBulletin 6.1.0 is available for download. Preview releases are for testing upcoming releases and should not be used on production servers...
Replies
0
Views
422
thxf.org 
  • Article Article
vBulletin 6.0.8 is now available for download by self-hosted (download) customers. vBulletin Cloud sites will be automatically updated in the upcoming weeks. Front End Changes Go to New Post A new...
Replies
0
Views
358
thxf.org 
  • Article Article
vBulletin 6.0.7 is now available for download by self-hosted (download) customers. vBulletin Cloud sites will be automatically updated in the upcoming weeks. Front End Changes Site Builder Quick...
Replies
0
Views
371
thxf.org 

กรุณาปิด โปรแกรมบล๊อกโฆษณา เพราะเราอยู่ได้ด้วยโฆษณาที่ท่านเห็น
Please close the adblock program. Because we can live with the ads you see
Back
Top Bottom