Page 1 of 2 1 2 LastLast
Results 1 to 15 of 24

vBulletin 3.7.2 PL1 and 3.6.10 PL3 Released

This is a discussion on vBulletin 3.7.2 PL1 and 3.6.10 PL3 Released within the vBulletin.com Announcements forums, part of the Announcements & Pre-Sales category; vBulletin 3.7.2 PL1 / vBulletin 3.6.10 PL3 An XSS flaw affecting the vBulletin control panel logging system has been identified, ...

  1. #1
    vBSEO Moderator vBulletin.com Staff's Avatar
    Join Date
    Oct 2009
    Posts
    411
    Liked
    6 times

    vBulletin 3.7.2 PL1 and 3.6.10 PL3 Released

    vBulletin 3.7.2 PL1 / vBulletin 3.6.10 PL3

    An XSS flaw affecting the vBulletin control panel logging system has been identified, another was found affecting boards running in debug mode. It could allow an attacker to trick an admin into unwittingly performing an action within the control panel that they had not intended. To resolve this issue, it is necessary to release patch level versions of vBulletin 3.7.2 and 3.6.10.

    One of the XSS flaws was discovered by Jessica Hope and the other by ourselves.

    The upgrade process is the same as previous patch level releases - simply download the patch from the Members Area, extract the files and upload to your webserver, overwriting the existing files. There is no upgrade script required.

    As with all security-based releases, we recommend that all customers upgrade as soon as possible in order to prevent any potential damage resulting from the flaw being exploited.


    Upgrading from 3.7.2, 3.6.10 or their patch level versions

    If you are already running 3.7.2, 3.6.10 or their patch level versions, the process you will be required to follow to make your board immune to the XSS problem is very simple.

    There is no need to run an upgrade script if you are already running 3.7.2, 3.6.10 or their patch level versions.

    Visit the Patches section of the vBulletin Members' Area and download either the patch for 3.7.2, or the patch for 3.6.10, according to the version you are currently running, then extract the files from the archive you downloaded, then upload the files to your board via FTP etc., overwriting the existing files. This will update your version to the PL1 or PL3 release respectively.

    The 3.6.10 PL3 patch file also includes the PL1 and PL2 fixes.


    Upgrading from Versions Earlier than 3.7.2 or 3.6.10

    If you are not already running 3.7.2 or 3.6.10, you should download the most latest version from the Members' Area and perform an upgrade as normal.

    Full instructions for upgrading vBulletin are available here.


    Download vBulletin 3.7.2 PL1 or 3.6.10 PL3

    As usual, both versions released today are available for all customers with valid, active licenses to download from the vBulletin Members' Area.

    vBulletin Members Area


    More...

  2. #2
    Senior Member snakeair's Avatar
    Real Name
    Derek
    Join Date
    Feb 2007
    Location
    USA, NJ
    Posts
    280
    Liked
    1 times
    Blog Entries
    7
    I just got done doing the update. No template changes which is good.

    Past 2 days, i've did a lot of updating on my forum. At least VB fixed some bug's that i had on my forum.

  3. #3
    vBSEO Staff Ace Shattock's Avatar
    Real Name
    Ace Shattock
    Join Date
    Jul 2005
    Location
    Auckland, New Zealand, New Zealand
    Posts
    3,999
    Liked
    11 times
    Who is this Jessica Hope person that keeps getting mentioned as an exploit finder?

    Should I know?

  4. #4
    Senior Member Lee G's Avatar
    Real Name
    Lee
    Join Date
    Sep 2006
    Location
    Costa Blanca
    Posts
    683
    Liked
    40 times
    Blog Entries
    4
    Glad I held off doing the last update. Two birds with one stone

    Just hope it don't mess up my latest forum efforts

  5. #5
    Senior Member snakeair's Avatar
    Real Name
    Derek
    Join Date
    Feb 2007
    Location
    USA, NJ
    Posts
    280
    Liked
    1 times
    Blog Entries
    7
    I have no idea and is this person actually a human or made up character?

    Does VB pay people to hack there software to find bugs or something?

  6. #6
    Senior Member briansol's Avatar
    Real Name
    Brian
    Join Date
    Apr 2006
    Location
    Central CT, USA
    Posts
    6,981
    Liked
    8 times

  7. #7
    Senior Member Lee G's Avatar
    Real Name
    Lee
    Join Date
    Sep 2006
    Location
    Costa Blanca
    Posts
    683
    Liked
    40 times
    Blog Entries
    4
    I'm sure there are plenty of people biting their lips with an answer to the last question.

    I'm waiting to see what Brian says

  8. #8
    Senior Member briansol's Avatar
    Real Name
    Brian
    Join Date
    Apr 2006
    Location
    Central CT, USA
    Posts
    6,981
    Liked
    8 times
    i don't know what vb does.

    there's plenty of 3rd party service out there, like scan alert (now mcaffe secure) etc that will place various tests on your sites. vbseo in fact runs this same service.

  9. #9
    Senior Member
    Real Name
    Matt
    Join Date
    May 2006
    Posts
    973
    Liked
    3 times
    Upgraded both my sites within minutes.

    ps. I hope everyone here is using different admincp and modcp directories on there forums.

  10. #10
    Senior Member briansol's Avatar
    Real Name
    Brian
    Join Date
    Apr 2006
    Location
    Central CT, USA
    Posts
    6,981
    Liked
    8 times
    IMO, these aren't even a big deal. you just need to be careful about what you click and when you click it. XSS are usually easy to detect/notice just by watching the status bar load

  11. #11
    Senior Member snakeair's Avatar
    Real Name
    Derek
    Join Date
    Feb 2007
    Location
    USA, NJ
    Posts
    280
    Liked
    1 times
    Blog Entries
    7
    Thanks for the info Brian. I didn't even know this.

  12. #12
    Senior Member
    Real Name
    Alex
    Join Date
    Mar 2007
    Location
    Italy
    Posts
    508
    Liked
    0 times
    Quote Originally Posted by hornstar6969 View Post

    ps. I hope everyone here is using different admincp and modcp directories on there forums.
    Hello, what you mean?

  13. #13
    Senior Member Shadab's Avatar
    Real Name
    Shadab
    Join Date
    Oct 2007
    Location
    Bhopal
    Posts
    821
    Liked
    0 times
    Blog Entries
    12
    Quote Originally Posted by meonet View Post
    Hello, what you mean?
    Means changing the directories of Admin Control Panel and Moderation control panel.
    The default are : admincp/ and modcp/

    Changing them to something obscure like :

    admincp-hackers-cant-get-here/
    modcp-not-here-too/

    should be good

  14. #14
    Senior Member
    Real Name
    Alex
    Join Date
    Mar 2007
    Location
    Italy
    Posts
    508
    Liked
    0 times
    Quote Originally Posted by Shadab View Post
    Means changing the directories of Admin Control Panel and Moderation control panel.
    The default are : admincp/ and modcp/

    Changing them to something obscure like :

    admincp-hackers-cant-get-here/
    modcp-not-here-too/

    should be good
    Oh ok thanks

  15. #15
    Senior Member
    Real Name
    Michael Biddle
    Join Date
    Jan 2007
    Location
    Southern California
    Posts
    7,097
    Liked
    4 times
    However if you choose to do this, be sure that you update the path in your config.php
    The Forum Hosting - Forum Hosting from the Forum Experts

Page 1 of 2 1 2 LastLast

Similar Threads

  1. vBulletin 3.7.1 PL1 & 3.6.10 PL1 Released
    By vBulletin.com Staff in forum vBulletin.com Announcements
    Replies: 3
    Last Post: 06-09-2008, 01:31 PM
  2. vBulletin 3.6.10 Released
    By vBulletin.com Staff in forum vBulletin.com Announcements
    Replies: 0
    Last Post: 04-23-2008, 02:00 PM
  3. vBulletin 3.6.2 released
    By Mert Gökçeimam in forum Off-Topic & Chit Chat
    Replies: 9
    Last Post: 10-05-2006, 09:42 PM
  4. vBulletin 3.6.1 Released
    By 10085998 in forum General Discussion
    Replies: 27
    Last Post: 09-15-2006, 11:57 PM
  5. vBulletin 3.5.1, 3.0.10 Released
    By Keith Cohen in forum Off-Topic & Chit Chat
    Replies: 5
    Last Post: 11-02-2005, 12:17 PM

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •