กรุณาปิด โปรแกรมบล๊อกโฆษณา เพราะเราอยู่ได้ด้วยโฆษณาที่ท่านเห็น
Please close the adblock program. Because we can live with the ads you see


thxf.org

Annon vBulletin 4.0.0 PL1, 3.8.4 PL2, and 3.7.6 PL2 Released

An exploit in our input validation has recently been discovered. This could allow a brute force attack to comprise and spoof input data for a given user. To resolve this issue, it is necessary to release a patch level version of the active versions of vBulletin.

The upgrade process is the same as previous patch level releases - simply download the patch from the Members Area, extract the files and upload to your webserver, overwriting the existing files. There is no upgrade script required.

As with all security-based releases, we recommend that all customers upgrade as soon as possible in order to prevent any potential damage resulting from the flaw being exploited.

If you are already running 3.7.6, 3.8.4 or 4.0.0, the process you will be required to follow to make your board immune to this flaw is very simple.

There is no need to run an upgrade script if you are already running the latest version.

Visit the Patches section of the vBulletin Members' Area and download the patch for the version you are using, then extract the files from the archive you downloaded, then upload the files to your board via FTP etc., overwriting the existing files. This will update your version to the latest patch release.

Upgrading from an earlier version

If you are not already running 3.7.6 or 3.8.4, you should download the latest version from the Members' Area and perform an upgrade as normal.

Full instructions for upgrading vBulletin are available here.


Download vBulletin 4.0.0 PL1 / 3.8.4 PL2 / 3.7.6 PL 2

As usual, the version released today is available for all customers with valid, active licenses to download from the vBulletin Members' Area.

vBulletin Members Area


More...
 


Similar threads

  • Article Article
Further to the issue that was rectified with vB 4.0.8 PL1, an additional concern was identified that may affect users utilizing IE6. The flaw may enable users to upload a script to their own...
Replies
0
Views
2K
thxf.org 
  • Article Article
There was an issue identified in vBulletin 4.1.0 and 4.1.0 PL1 that may potentially break a number of 3rd party plugins and modifications. Please note, this issue does not affect the core...
Replies
0
Views
3K
thxf.org 
  • Article Article
[SIZE=4]vBulletin Publishing suite and Forum Classic 4.1.5pl1 4.1.4pl3 4.1.3pl3 Has been released. This patch strengthens the security of the AdminCP to prevent a reported XSS attack in vBulletin...
Replies
1
Views
2K
Nataro
  • Article Article
[SIZE=4]vBulletin 3.8.4 PL1 / 3.7.6 PL1 / 3.6.12 PL2 An XSS flaw within the user profile page has recently been discovered. This could allow an attacker to carry out an action as a user or obtain...
Replies
0
Views
3K
thxf.org 
  • Article Article
Yahoo YUI Security Exploit We have been notified of a potential, but unconfirmed exploit in vBulletin 3 and 4 (all versions) via the Yahoo YUI component library. To rectify this issue we have...
Replies
0
Views
2K
thxf.org 

กรุณาปิด โปรแกรมบล๊อกโฆษณา เพราะเราอยู่ได้ด้วยโฆษณาที่ท่านเห็น
Please close the adblock program. Because we can live with the ads you see
Back
Top Bottom