vBulletin SEO Forums

SEO

vBulletin Search Engine Optimization

Buy vBSEO Now!
vBSEO 2.0 Style Released vBSEO 3.3.0 GOLD Launched vBSEO's "LiveStats" for Google Analytics vB Sitemap Generator, Version 2.5 Success with vBSEO = 600ore Web Visitors + $1400 in a Day!

vBulletin 3.7.4 PL1 Released

This is a discussion on vBulletin 3.7.4 PL1 Released within the vBulletin.com Announcements forums, part of the Announcements & Pre-Sales category; vBulletin 3.7.4 PL1 An XSS flaw within the user control panel has recently been discovered. This could allow an attacker ...

Go Back   vBulletin SEO Forums > Announcements & Pre-Sales > vBulletin.com Announcements

Enhancing 80 million pages.


Reply

 

LinkBack Thread Tools
  #1  
Old 11-21-2008, 06:30 AM
Joe Ward's Avatar
vBSEO Staff
vBSEO Total Customer SupportvBSEO Documenter
 
Real Name: Joseph Ward
Join Date: Jun 2005
Location: Puerto Rico
Posts: 24,060
Blog Entries: 9
vBulletin 3.7.4 PL1 Released

vBulletin 3.7.4 PL1

An XSS flaw within the user control panel has recently been discovered. This could allow an attacker to carry out an action as a user or obtain access to a user's account. To resolve this issue, it is necessary to release a patch level version of vBulletin 3.7.4.

vBulletin 3.6 is not affected. vBulletin 3.8 is affected, and the next beta/release candidate will include the fix.

The upgrade process is the same as previous patch level releases - simply download the patch from the Members Area, extract the files and upload to your webserver, overwriting the existing files. There is no upgrade script required.

As with all security-based releases, we recommend that all customers upgrade as soon as possible in order to prevent any potential damage resulting from the flaw being exploited.


Upgrading from 3.7.4

If you are already running 3.7.4, the process you will be required to follow to make your board immune to this flaw is very simple.

There is no need to run an upgrade script if you are already running 3.7.4.

Visit the Patches section of the vBulletin Members' Area and download the patch for 3.7.4, then extract the files from the archive you downloaded, then upload the files to your board via FTP etc., overwriting the existing files. This will update your version to the PL1 release.


Upgrading from Versions Earlier than 3.7.4

If you are not already running 3.7.4, you should download the latest version from the Members' Area and perform an upgrade as normal.

Full instructions for upgrading vBulletin are available here.


Download vBulletin 3.7.4 PL1

As usual, the version released today is available for all customers with valid, active licenses to download from the vBulletin Members' Area.

vBulletin Members Area


More...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #2  
Old 11-21-2008, 10:32 AM
Senior Member
 
Real Name: Johnny5
Join Date: Oct 2008
Posts: 166
Has anyone performed the upgrade and verified that it plays nice with the current version of vbseo?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #3  
Old 11-21-2008, 11:02 AM
Mert Gökçeimam's Avatar
vBSEO.com Webmaster
vBSEO Total Customer SupportDesign for SEOBig Board Administrator
 
Real Name: Lizard King
Join Date: Oct 2005
Location: Istanbul
Posts: 13,216
Blog Entries: 4
Send a message via MSN to Mert Gökçeimam
As it is a security upgrade you should worry about it .
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #4  
Old 11-21-2008, 12:14 PM
Junior Member
 
Real Name: Yunus
Join Date: Nov 2008
Location: Mersin ,Tarsus ,Türkiye
Posts: 8
I did it,thanks
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #5  
Old 11-21-2008, 12:49 PM
Junior Member
 
Real Name: David
Join Date: Oct 2008
Posts: 7
Question about config.php

Yes I'm a newbie.
First upgrage of VB from 3.7.3 to 3.7.4 PL1
Have VBSEO on the 3.7.3 and I have a question before I start.

Do I have to grab the old vBSEOconfig.php from the old includes file or is there a step to do that later?

Seems that the answer would be to just copy that file to the new package during the upload. 1st time so being extra cautious.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #6  
Old 11-21-2008, 12:56 PM
Shadab's Avatar
Senior Member
 
Real Name: Shadab
Join Date: Oct 2007
Location: Bhopal
Posts: 687
Blog Entries: 12
Send a message via ICQ to Shadab Send a message via MSN to Shadab Send a message via Yahoo to Shadab Send a message via Skype™ to Shadab
@David: Heres what I do to upgrade vB :

- Upload the new vBulletin files via FTP overwriting the old ones.
- Perform the upgrade (/install/upgrade.php)

This way, the files belonging to any mods aren't touched. And they will function without any problem. (I then update the installed modifications, one by one, if needed, to be compatible with the new vBulletin version).
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #7  
Old 11-22-2008, 02:13 PM
Brandon Sheley's Avatar
Senior Member
vBSEO Pre-Release Team
 
Real Name: Brandon Sheley
Join Date: Oct 2005
Location: Kansas
Posts: 2,032
Blog Entries: 1
Send a message via AIM to Brandon Sheley Send a message via MSN to Brandon Sheley Send a message via Yahoo to Brandon Sheley
I just uploaded the patch
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #8  
Old 11-22-2008, 05:20 PM
Senior Member
Big Board Administrator
 
Real Name: Matt
Join Date: May 2006
Posts: 751
I went from 3.7.3 to this update, all went smooth.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #9  
Old 11-22-2008, 06:31 PM
Shazz's Avatar
Senior Member
 
Real Name: Shawn
Join Date: Sep 2006
Location: SoundDistrict.com
Posts: 129
Send a message via AIM to Shazz Send a message via MSN to Shazz Send a message via Yahoo to Shazz
I have a feeling when I upgrade to this 3.8 gold will be out :(
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #10  
Old 11-22-2008, 08:20 PM
Senior Member
Big Board Administrator
 
Real Name: Matt
Join Date: May 2006
Posts: 751
upgrading only takes minutes unless you have really gone overboard on customizations in your skin or you have purchased a skin that is really heavily modified it wont take long at all. Even on my purchased skin which is a bit modified, it is really easy to tell what needs updating and only takes a minute or two longer.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #11  
Old 11-22-2008, 09:20 PM
Shazz's Avatar
Senior Member
 
Real Name: Shawn
Join Date: Sep 2006
Location: SoundDistrict.com
Posts: 129
Send a message via AIM to Shazz Send a message via MSN to Shazz Send a message via Yahoo to Shazz
Quote:
Originally Posted by hornstar6969 View Post
unless you have really gone overboard on customizations in your skin
Exactly what I have...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #12  
Old 11-23-2008, 12:55 AM
briansol's Avatar
Senior Member
 
Real Name: Brian
Join Date: Apr 2006
Location: Central CT, USA
Posts: 7,090
over-paranoid IMO.

xss isn't going to get you hacked... only stupid users will fall for it and it won't effect your site, only their machine basically...
OR, they enter their login information in an xss iframe of some sort...
so, just tell your staff to be careful about how they log in and you have nothing to worry about IMO.

I won't b upgrading.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #13  
Old 11-25-2008, 05:39 AM
Junior Member
 
Real Name: Julian
Join Date: Mar 2008
Posts: 2
we have serious performance problems after upgrading to 3.7.4 PL1

anyone else noticed something in this direction? maybe it's another problem..
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #14  
Old 11-25-2008, 03:33 PM
Senior Member
Big Board Administrator
 
Real Name: Matt
Join Date: May 2006
Posts: 751
I have not noticed an increase my self.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
  #15  
Old 11-25-2008, 04:41 PM
Misafir's Avatar
Member
Big Board Administrator
 
Real Name: Misafir
Join Date: Feb 2007
Location: İstanbul
Posts: 68
Blog Entries: 1
I just updated from 3.7.1 to this update
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Share on Facebook!
Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads

Thread Thread Starter Forum Replies Last Post
vBulletin 3.7.3 PL1 and 3.6.11 PL1 Released Joe Ward vBulletin.com Announcements 3 09-04-2008 02:54 PM
vBulletin 3.6.11 Released Joe Ward vBulletin.com Announcements 0 08-26-2008 07:00 AM
vBulletin 3.7.1 PL1 & 3.6.10 PL1 Released Joe Ward vBulletin.com Announcements 3 06-09-2008 12:31 PM
vBulletin 3.6.10 Released Joe Ward vBulletin.com Announcements 0 04-23-2008 01:00 PM
vBulletin 3.5.1, 3.0.10 Released Keith Cohen Off-Topic & Chit Chat 5 11-02-2005 11:17 AM


All times are GMT -4. The time now is 11:44 AM.


Powered by vBulletin Version 3.8.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.0 ©2009, Crawlability, Inc.