กรุณาปิด โปรแกรมบล๊อกโฆษณา เพราะเราอยู่ได้ด้วยโฆษณาที่ท่านเห็น
Please close the adblock program. Because we can live with the ads you see


thxf.org

ประกาศ vBulletin Security Patch for vBulletin 4.1.12 for Suite & Forum - 04/23/2012

  • ผู้เริ่มหัวข้อ ผู้เริ่มหัวข้อ thxf.org 
  • วันที่เริ่มต้น วันที่เริ่มต้น
vBulletin has released a security patch to improve the security of the vBulletin 4 MAPI for 4.1.12 Suite & Forum as the result of a recent internal security review. Although no exploits have been reported, we urge our customers to upgrade as soon as possible.

The changes do not affect vBulletin 4.0.0 - 4.1.1.

This patch has been issued for vBulletin 4.1.12. A separate set of patches have been issued for vBulletin 4.1.2 - 4.1.11.

The MAPI security improvements have been added for vBulletin 3.x with the release of 3.x MAPI 1.4.3.

To improve the security of your vBulletin 4 installation, please download the patch from the members area of vBulletin:Please Log In

In addition to the security improvements, we've resolved the following 4.1.12 issues.

  • VBIV-14742 - Push notifications broken in FR 4.1.12 add-on.
  • VBIV-14685 - Tag in static page cause Fatal error on page with General Search widget set to return Static Pages
  • VBIV-14663 - Quoting doesn't work in the mobile style
  • VBIV-14660 - Static HTML in CMS always displays all content
  • VBIV-14754 - unset($VB_API_PARAMS_TO_VERIFY['vbseourl']) to match vB3 MAPI change.
  • VBIV-14681 - HTML is stripped from article previews
  • VBIV-14667 - Category pages do not load if using basic/advanced friendly URLs

The upgrade process is slightly more complicated for this patch level release.


  • Download PL1 for vBulletin 4.1.12 from https://members.vbulletin.com.
  • Upload the patch do your server.
  • Unzip the patch to your vBulletin 4 install directory. (Ex. /var/www/html/myforum)
  • Run ./install/upgrade.php. (Required for 4.1.12.)
  • Download the "API-Log-Clean.xml" attached to this thread. (Included in the do_not_upload folder for full installs.)
  • Import "API-Log-Clean.xml" using the "Manage Products" interface in the "Plugins & Products" section of your Admin CP. The cleanup script will run on install. AdminCP -> Plugins & Products -> Manage Products -> Add/Import Product
  • Delete "API-Log-Clean" using the "Product Manager" option in the "Plugins & Products" section of your Admin CP. (Optional. The product is automatically disabled after the script runs.)

Advanced Users - Files updated in the patch are:

  • /api.php
  • /forumrunner/push.php
  • /includes/class_friendly_url.php
  • /includes/init.php
  • /install/vbulletin-mobile-style-blog.xml
  • /install/vbulletin-mobile-style.xml
  • /packages/vbcms/content/phpeval.php
  • /packages/vbcms/content/staticpage.php
  • /packages/vbcms/item/content/article.php
  • /packages/vbcms/item/content/phpeval.php
  • /packages/vbcms/search/result/staticpage.php
Please note that this issue and fix affects BOTH vBulletin 4 SUITE and FORUM.

Discuss the security patch - HERE

Discuss vBulletin 4.1.12 - HERE
Attached Files
  • 1.jpg
    API-Log-Clean.xml‎ (1.9 KB)



More...
 

กระทู้ที่คล้ายกัน

  • บทความ บทความ
vBulletin 6.0.8 is now available for download by self-hosted (download) customers. vBulletin Cloud sites will be automatically updated in the upcoming weeks. Front End Changes Go to New Post A new...
ตอบกลับ
0
จำนวนการดู
301
thxf.org 
  • บทความ บทความ
vBulletin 6.1.1 Changes and Updates vBulletin 6.1.1 is now available to download. In the upcoming weeks, vBulletin Cloud customers will be automatically upgraded to the new version. Front End...
ตอบกลับ
1
จำนวนการดู
299
thxf.org 
  • บทความ บทความ
vBulletin 6.1.0 Changes and Updates A preview release of vBulletin 6.1.0 is available for download. Preview releases are for testing upcoming releases and should not be used on production servers...
ตอบกลับ
0
จำนวนการดู
390
thxf.org 
  • บทความ บทความ
The API functionality of vBulletin 6 and 5.7.5 has been found to have security issues. We have created fixes for these issues. To maintain site security, you should apply this patch as soon as...
ตอบกลับ
0
จำนวนการดู
106
thxf.org 
  • บทความ บทความ
vBulletin 6.0.5 is now available for download by self-hosted (download) customers. vBulletin Cloud sites will be automatically updated in the upcoming weeks. Front End Changes Global Advertising...
ตอบกลับ
0
จำนวนการดู
436

กรุณาปิด โปรแกรมบล๊อกโฆษณา เพราะเราอยู่ได้ด้วยโฆษณาที่ท่านเห็น
Please close the adblock program. Because we can live with the ads you see
กลับ
ยอดนิยม ด้านล่าง