กรุณาปิด โปรแกรมบล๊อกโฆษณา เพราะเราอยู่ได้ด้วยโฆษณาที่ท่านเห็น
Please close the adblock program. Because we can live with the ads you see


thxf.org

ประกาศ vBulletin Security Patch for 4.X and 3.X

  • ผู้เริ่มหัวข้อ ผู้เริ่มหัวข้อ thxf.org 
  • วันที่เริ่มต้น วันที่เริ่มต้น
Yahoo YUI Security Exploit

We have been notified of a potential, but unconfirmed exploit in vBulletin 3 and 4 (all versions) via the Yahoo YUI component library.
To rectify this issue we have released a patch for the latest version of vBulletin 3 and vBulletin 4, vBulletin 3.8.7 and vBulletin 4.1.3. Forthcoming vBulletin 4.1.4 will not be affected.
As such, we have released:
  • vBulletin Publishing Suite 4.1.3 PL1
  • vBulletin Forum Classic 4.1.3 PL1
  • vBulletin Forum Classic 3.8.7 PL1

Upgrade Process
The upgrade process is the same as previous patch level releases - simply download the patch from theMembers Area, extract the files and upload to your webserver, overwriting the existing files. There is no upgrade script required.
As with all security-based releases, we recommend that all customers upgrade as soon as possible in order to prevent any potential damage resulting from the flaw being exploited.



New installations/upgrades
If you are upgrading your site, or installing a new copy of our software, the latest software packages include the patch. These can be downloaded from your Members Area



To manually fix versions prior to vBulletin 4.1.3 and 3.8.7
  1. Edit one line in class_core.php file located in /includes/class_core.php ; find the following line “define('YUI_VERSION', '2.7.0'); // define the YUI version we bundle” ; replace this line with “define('YUI_VERSION', '2.9.0'); // define the YUI version we bundle”
  2. In AdminCP; Go to “Options” => “Server Settings and Optimization Options” ; find “Use Remote YUI” option and in the dropdown switch to a server of your choice, Google or Yahoo.


More...
 

กระทู้ที่คล้ายกัน

  • บทความ บทความ
The API functionality of vBulletin 6 and 5.7.5 has been found to have security issues. We have created fixes for these issues. To maintain site security, you should apply this patch as soon as...
ตอบกลับ
0
จำนวนการดู
106
thxf.org 
  • บทความ บทความ
This patch solves three issues: how the system detects PHAR files, a potential security issue in BBCode rendering, and a problem with inviting members to a Blog. Self-hosted customers should apply...
ตอบกลับ
0
จำนวนการดู
389
thxf.org 
  • บทความ บทความ
A security issue has been found in the AdminCP log in functionality of vBulletin 6.0.0 and 5.7.5. This security patch addresses the concerns outlined in CVE-2023-39777. We have created a fix for...
ตอบกลับ
0
จำนวนการดู
243
thxf.org 
  • บทความ บทความ
A security update with respect to custom avatars has been made by vBulletin in the following security patch. You can download the patch for your version in the Member's Area We have made patches...
ตอบกลับ
0
จำนวนการดู
1พัน
thxf.org 
  • บทความ บทความ
Two potential issues have been identified in vBulletin 5.3.2 and higher. The first affects the template rendering functionality and could lead to arbitrary file deletion. The second allows the...
ตอบกลับ
0
จำนวนการดู
1พัน
thxf.org 

กรุณาปิด โปรแกรมบล๊อกโฆษณา เพราะเราอยู่ได้ด้วยโฆษณาที่ท่านเห็น
Please close the adblock program. Because we can live with the ads you see
กลับ
ยอดนิยม ด้านล่าง