vBulletin SEO Forums

SEO

vBulletin Search Engine Optimization

Buy vBSEO Now! HACKER SAFE certified sites prevent over 99.9% of hacker crime.
ne nw
vBSEO Total Support Team Launches DeskPro New vBSEO Discount Level for Network Builders vBSEO 3.2.0 GOLD Has Landed Success with vBSEO = 600ore Web Visitors + $1400 in a Day! Crawlability Inc. Files for SEO Technology Patent
se sw

vBulletin 3.7.2 PL2 and 3.6.10 PL4 Released

This is a discussion on vBulletin 3.7.2 PL2 and 3.6.10 PL4 Released within the vBulletin.com Announcements forums, part of the Announcements & Pre-Sales category; vBulletin 3.7.2 PL2 / vBulletin 3.6.10 PL4 An XSS flaw related to JavaScript escaping has been identified. This could allow ...

Go Back   vBulletin SEO Forums > Announcements & Pre-Sales > vBulletin.com Announcements

Enhancing 80 million pages.

Register FAQ Members List Social Groups Calendar Search Today's Posts Mark Forums Read
  #1  
Old 08-18-2008, 07:10 AM
Joe Ward's Avatar
vBSEO Staff
vBSEO Total Customer SupportvBSEO Documenter
 
Real Name: Joseph Ward
Join Date: Jun 2005
Location: Puerto Rico
Posts: 19,746
Blog Entries: 7
vBulletin 3.7.2 PL2 and 3.6.10 PL4 Released

vBulletin 3.7.2 PL2 / vBulletin 3.6.10 PL4

An XSS flaw related to JavaScript escaping has been identified. This could allow an attacker to carry out an action as a user or obtain access to a user's account. To resolve this issue, it is necessary to release patch level versions of vBulletin 3.7.2 and 3.6.10.

This flaw was discovered by Federico Muttis.

The upgrade process is the same as previous patch level releases - simply download the patch from the Members Area, extract the files and upload to your webserver, overwriting the existing files. There is no upgrade script required.

As with all security-based releases, we recommend that all customers upgrade as soon as possible in order to prevent any potential damage resulting from the flaw being exploited.


vBulletin 3.7.3 and 3.6.11 to be Released Next Week

In line with our new scheduled maintenance release policy, a new release for 3.6 and 3.7 will be made on Tuesday, August 26th.

These releases will contain bug fixes, but will also address a situation related to users that use their username as their password. In 3.6.11 and 3.7.3, this will be completely disallowed. Users affected by this will be forced to change their password on their first login. Additionally, a tool will be provided to email affected users with a new password. Please be aware of these potential compatibility changes when upgrading.

This release will be mentioned in the security bulletin sent out to customers today, but we will not send a further notification next week when 3.7.3 and 3.6.11 are released. Watch your Admin CP News, or the latest version check in the Admin CP to see when the new version is available. Alternatively, keep an eye on this forum for the 3.7.2 and 3.6.11 announcements.


Upgrading from 3.7.2, 3.6.10 or their patch level versions

If you are already running 3.7.2, 3.6.10 or their patch level versions, the process you will be required to follow to make your board immune to the XSS problem is very simple.

There is no need to run an upgrade script if you are already running 3.7.2, 3.6.10 or their patch level versions.

Visit the Patches section of the vBulletin Members' Area and download either the patch for 3.7.2, or the patch for 3.6.10, according to the version you are currently running, then extract the files from the archive you downloaded, then upload the files to your board via FTP etc., overwriting the existing files. This will update your version to the PL1 or PL3 release respectively.

The 3.7.2 PL2 patch file includes the PL1 fix.
The 3.6.10 PL4 patch file also includes the PL1, PL2, and PL3 fixes.


Upgrading from Versions Earlier than 3.7.2 or 3.6.10

If you are not already running 3.7.2 or 3.6.10, you should download the most latest version from the Members' Area and perform an upgrade as normal.

Full instructions for upgrading vBulletin are available here.


Download vBulletin 3.7.2 PL2 or 3.6.10 PL4

As usual, both versions released today are available for all customers with valid, active licenses to download from the vBulletin Members' Area.

vBulletin Members Area


More...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #2  
Old 08-18-2008, 05:47 PM
Senior Member
 
Real Name: Derek
Join Date: Feb 2007
Location: USA, NJ
Posts: 271
Blog Entries: 3
I was itching to update something since i returned from my vacation. This little patch was the fix.

I like the next release though. 3.7.3 with the "no username as password" thing. I'm wondering if any of my members are doing this on the forum or other forum's.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #3  
Old 08-18-2008, 05:54 PM
briansol's Avatar
Senior Member
vBSEO Pre-Release TeamDesign for SEOBig Board Administrator
 
Real Name: Brian
Join Date: Apr 2006
Location: Central CT, USA
Posts: 5,538
Quote:
Originally Posted by snakeair View Post
I like the next release though. 3.7.3 with the "no username as password" thing.
link?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #4  
Old 08-18-2008, 06:00 PM
Ace Shattock's Avatar
vBSEO Staff
vBSEO Total Customer SupportCommunity Builder
 
Real Name: Ace Shattock
Join Date: Jul 2005
Location: New Zealand
Posts: 2,923
vBulletin 3.7.2 PL2 and 3.6.10 PL4 Released - vBulletin Community Forum

__________________
Ace Shattock / Crawlability Inc.
Support Team Launches New DeskPro Powered Tool Enhanced Support at Your Service

vBSEO 3.2.0 Launched - Maximum Overdrive for Your Web Traffic! Over 100 Instant SEO Optimizations

6X Traffic - $1400 in One Day with vBSEO! Imagine What the vBSEO Patent Pending Technology Can Do For You.


My Personal Sites: New Zealand Forum | vBulletin Modifications and Styles | vBulletin Hosting
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #5  
Old 08-18-2008, 06:07 PM
briansol's Avatar
Senior Member
vBSEO Pre-Release TeamDesign for SEOBig Board Administrator
 
Real Name: Brian
Join Date: Apr 2006
Location: Central CT, USA
Posts: 5,538
oh. reading > me
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads

Thread Thread Starter Forum Replies Last Post
vBulletin 3.7.2 Released Joe Ward vBulletin.com Announcements 22 06-27-2008 08:31 AM
vBulletin 3.7.1 PL2 and 3.6.10 PL2 Released Joe Ward vBulletin.com Announcements 3 06-19-2008 01:26 PM
vBulletin 3.7.1 PL1 & 3.6.10 PL1 Released Joe Ward vBulletin.com Announcements 3 06-09-2008 01:31 PM
vBulletin 3.6.10 Released Joe Ward vBulletin.com Announcements 0 04-23-2008 02:00 PM
vBulletin 3.5.2, 3.0.11 Released Keith Cohen Off-Topic & Chit Chat 3 12-06-2005 03:14 PM


All times are GMT -4. The time now is 10:13 PM.


Powered by vBulletin Version 3.8.0 Beta 4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.5 ©2008, Crawlability, Inc.