Page 1 of 2 1 2 LastLast
Results 1 to 15 of 16

vBulletin 3.7.4 PL1 Released

This is a discussion on vBulletin 3.7.4 PL1 Released within the vBulletin.com Announcements forums, part of the Announcements & Pre-Sales category; vBulletin 3.7.4 PL1 An XSS flaw within the user control panel has recently been discovered. This could allow an attacker ...

  1. #1
    vBSEO Moderator vBulletin.com Staff's Avatar
    Join Date
    Oct 2009
    Posts
    408
    Liked
    6 times

    vBulletin 3.7.4 PL1 Released

    vBulletin 3.7.4 PL1

    An XSS flaw within the user control panel has recently been discovered. This could allow an attacker to carry out an action as a user or obtain access to a user's account. To resolve this issue, it is necessary to release a patch level version of vBulletin 3.7.4.

    vBulletin 3.6 is not affected. vBulletin 3.8 is affected, and the next beta/release candidate will include the fix.

    The upgrade process is the same as previous patch level releases - simply download the patch from the Members Area, extract the files and upload to your webserver, overwriting the existing files. There is no upgrade script required.

    As with all security-based releases, we recommend that all customers upgrade as soon as possible in order to prevent any potential damage resulting from the flaw being exploited.


    Upgrading from 3.7.4

    If you are already running 3.7.4, the process you will be required to follow to make your board immune to this flaw is very simple.

    There is no need to run an upgrade script if you are already running 3.7.4.

    Visit the Patches section of the vBulletin Members' Area and download the patch for 3.7.4, then extract the files from the archive you downloaded, then upload the files to your board via FTP etc., overwriting the existing files. This will update your version to the PL1 release.


    Upgrading from Versions Earlier than 3.7.4

    If you are not already running 3.7.4, you should download the latest version from the Members' Area and perform an upgrade as normal.

    Full instructions for upgrading vBulletin are available here.


    Download vBulletin 3.7.4 PL1

    As usual, the version released today is available for all customers with valid, active licenses to download from the vBulletin Members' Area.

    vBulletin Members Area


    More...

  2. #2
    Senior Member
    Real Name
    Johnny5
    Join Date
    Oct 2008
    Posts
    231
    Liked
    0 times
    Has anyone performed the upgrade and verified that it plays nice with the current version of vbseo?

  3. #3
    vBSEO.com Webmaster Mert Gökçeimam's Avatar
    Real Name
    Lizard King
    Join Date
    Oct 2005
    Location
    Istanbul, Turkey, Turkey
    Posts
    22,362
    Liked
    540 times
    Blog Entries
    4
    As it is a security upgrade you should worry about it .
    Mert Gökçeimam / Crawlability Inc.

    vBSEO 3.6.0 Alpha Önizlemesi - Including Like Tree
    Unveiling the NEW vBSEO Sitemap Generator 3.0 - available NOW for vBSEO Customers!


    Twitter:@Depkac
    Personal Blog : Mert Gökçeimam

  4. #4
    Junior Member
    Real Name
    Yunus
    Join Date
    Nov 2008
    Location
    Mersin ,Tarsus ,Türkiye
    Posts
    8
    Liked
    0 times
    I did it,thanks

  5. #5
    Junior Member
    Real Name
    David
    Join Date
    Oct 2008
    Posts
    7
    Liked
    0 times

    Question about config.php

    Yes I'm a newbie.
    First upgrage of VB from 3.7.3 to 3.7.4 PL1
    Have VBSEO on the 3.7.3 and I have a question before I start.

    Do I have to grab the old vBSEOconfig.php from the old includes file or is there a step to do that later?

    Seems that the answer would be to just copy that file to the new package during the upload. 1st time so being extra cautious.

  6. #6
    Senior Member Shadab's Avatar
    Real Name
    Shadab
    Join Date
    Oct 2007
    Location
    Bhopal
    Posts
    821
    Liked
    0 times
    Blog Entries
    12
    @David: Heres what I do to upgrade vB :

    - Upload the new vBulletin files via FTP overwriting the old ones.
    - Perform the upgrade (/install/upgrade.php)

    This way, the files belonging to any mods aren't touched. And they will function without any problem. (I then update the installed modifications, one by one, if needed, to be compatible with the new vBulletin version).

  7. #7
    Senior Member Brandon Sheley's Avatar
    Real Name
    Brandon Sheley
    Join Date
    Oct 2005
    Location
    Kansas
    Posts
    2,347
    Liked
    19 times
    Blog Entries
    1
    I just uploaded the patch
    My forums: General Forums | Admin Talk (running xenforo)

  8. #8
    Senior Member
    Real Name
    Matt
    Join Date
    May 2006
    Posts
    973
    Liked
    3 times
    I went from 3.7.3 to this update, all went smooth.

  9. #9
    Senior Member Shazz's Avatar
    Real Name
    Shawn
    Join Date
    Sep 2006
    Location
    SoundDistrict.com
    Posts
    129
    Liked
    0 times
    I have a feeling when I upgrade to this 3.8 gold will be out :(

  10. #10
    Senior Member
    Real Name
    Matt
    Join Date
    May 2006
    Posts
    973
    Liked
    3 times
    upgrading only takes minutes unless you have really gone overboard on customizations in your skin or you have purchased a skin that is really heavily modified it wont take long at all. Even on my purchased skin which is a bit modified, it is really easy to tell what needs updating and only takes a minute or two longer.

  11. #11
    Senior Member Shazz's Avatar
    Real Name
    Shawn
    Join Date
    Sep 2006
    Location
    SoundDistrict.com
    Posts
    129
    Liked
    0 times
    Quote Originally Posted by hornstar6969 View Post
    unless you have really gone overboard on customizations in your skin
    Exactly what I have...

  12. #12
    Senior Member briansol's Avatar
    Real Name
    Brian
    Join Date
    Apr 2006
    Location
    Central CT, USA
    Posts
    6,981
    Liked
    8 times
    over-paranoid IMO.

    xss isn't going to get you hacked... only stupid users will fall for it and it won't effect your site, only their machine basically...
    OR, they enter their login information in an xss iframe of some sort...
    so, just tell your staff to be careful about how they log in and you have nothing to worry about IMO.

    I won't b upgrading.

  13. #13
    Junior Member
    Real Name
    Julian
    Join Date
    Mar 2008
    Posts
    9
    Liked
    0 times
    we have serious performance problems after upgrading to 3.7.4 PL1

    anyone else noticed something in this direction? maybe it's another problem..

  14. #14
    Senior Member
    Real Name
    Matt
    Join Date
    May 2006
    Posts
    973
    Liked
    3 times
    I have not noticed an increase my self.

  15. #15
    Member Misafir's Avatar
    Real Name
    Misafir
    Join Date
    Mar 2007
    Location
    İstanbul
    Posts
    80
    Liked
    0 times
    Blog Entries
    1
    I just updated from 3.7.1 to this update

Page 1 of 2 1 2 LastLast

Similar Threads

  1. vBulletin 3.7.3 PL1 and 3.6.11 PL1 Released
    By vBulletin.com Staff in forum vBulletin.com Announcements
    Replies: 3
    Last Post: 09-04-2008, 03:54 PM
  2. vBulletin 3.6.11 Released
    By vBulletin.com Staff in forum vBulletin.com Announcements
    Replies: 0
    Last Post: 08-26-2008, 08:00 AM
  3. vBulletin 3.7.1 PL1 & 3.6.10 PL1 Released
    By vBulletin.com Staff in forum vBulletin.com Announcements
    Replies: 3
    Last Post: 06-09-2008, 01:31 PM
  4. vBulletin 3.6.10 Released
    By vBulletin.com Staff in forum vBulletin.com Announcements
    Replies: 0
    Last Post: 04-23-2008, 02:00 PM
  5. vBulletin 3.5.1, 3.0.10 Released
    By Keith Cohen in forum Off-Topic & Chit Chat
    Replies: 5
    Last Post: 11-02-2005, 12:17 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •