Results 1 to 5 of 5

vBulletin Security Patch for vBulletin 4.1.12 for Suite & Forum - 04/23/2012

This is a discussion on vBulletin Security Patch for vBulletin 4.1.12 for Suite & Forum - 04/23/2012 within the vBulletin.com Announcements forums, part of the Announcements & Pre-Sales category; vBulletin has released a security patch to improve the security of the vBulletin 4 MAPI for 4.1.12 Suite & Forum ...

  1. #1
    vBSEO Moderator Array vBulletin.com Staff's Avatar
    Join Date
    Oct 2009
    Posts
    502
    Liked
    7 times

    vBulletin Security Patch for vBulletin 4.1.12 for Suite & Forum - 04/23/2012

    vBulletin has released a security patch to improve the security of the vBulletin 4 MAPI for 4.1.12 Suite & Forum as the result of a recent internal security review. Although no exploits have been reported, we urge our customers to upgrade as soon as possible.

    The changes do not affect vBulletin 4.0.0 - 4.1.1.

    This patch has been issued for vBulletin 4.1.12. A separate set of patches have been issued for vBulletin 4.1.2 - 4.1.11.

    The MAPI security improvements have been added for vBulletin 3.x with the release of 3.x MAPI 1.4.3.

    To improve the security of your vBulletin 4 installation, please download the patch from the members area of vBulletin: http://members.vbulletin.com/

    In addition to the security improvements, we've resolved the following 4.1.12 issues.


    • VBIV-14742 - Push notifications broken in FR 4.1.12 add-on.
    • VBIV-14685 - Tag in static page cause Fatal error on page with General Search widget set to return Static Pages
    • VBIV-14663 - Quoting doesn't work in the mobile style
    • VBIV-14660 - Static HTML in CMS always displays all content
    • VBIV-14754 - unset($VB_API_PARAMS_TO_VERIFY['vbseourl']) to match vB3 MAPI change.
    • VBIV-14681 - HTML is stripped from article previews
    • VBIV-14667 - Category pages do not load if using basic/advanced friendly URLs



    The upgrade process is slightly more complicated for this patch level release.



    1. Download PL1 for vBulletin 4.1.12 from https://members.vbulletin.com.
    2. Upload the patch do your server.
    3. Unzip the patch to your vBulletin 4 install directory. (Ex. /var/www/html/myforum)
    4. Run ./install/upgrade.php. (Required for 4.1.12.)
    5. Download the "API-Log-Clean.xml" attached to this thread. (Included in the do_not_upload folder for full installs.)
    6. Import "API-Log-Clean.xml" using the "Manage Products" interface in the "Plugins & Products" section of your Admin CP. The cleanup script will run on install. AdminCP -> Plugins & Products -> Manage Products -> Add/Import Product
    7. Delete "API-Log-Clean" using the "Product Manager" option in the "Plugins & Products" section of your Admin CP. (Optional. The product is automatically disabled after the script runs.)



    Advanced Users - Files updated in the patch are:


    • /api.php
    • /forumrunner/push.php
    • /includes/class_friendly_url.php
    • /includes/init.php
    • /install/vbulletin-mobile-style-blog.xml
    • /install/vbulletin-mobile-style.xml
    • /packages/vbcms/content/phpeval.php
    • /packages/vbcms/content/staticpage.php
    • /packages/vbcms/item/content/article.php
    • /packages/vbcms/item/content/phpeval.php
    • /packages/vbcms/search/result/staticpage.php


    Please note that this issue and fix affects BOTH vBulletin 4 SUITE and FORUM.

    Discuss the security patch - HERE
    Discuss vBulletin 4.1.12 - HERE
    Attached Files




    More...

  2. #2
    Member Array
    Real Name
    Ghostman
    Join Date
    Feb 2011
    Posts
    47
    Liked
    1 times
    It seems that the function "promote to article" does not work with vbseo.

    Try to:
    take a thread-> promote to article -> save the promoted article -> error 404

  3. #3
    vBSEO Staff Array Andrés Durán Hewitt's Avatar
    Real Name
    Andrés Durán
    Join Date
    Jul 2009
    Location
    Costa Rica
    Posts
    3,861
    Liked
    569 times
    Blog Entries
    2
    Andrés Durán / Crawlability Inc.
    ˇvBSEO 3.6.0 GOLD Liberado!
    Inaugurando el NUEVO vBSEO Sitemap Generator 3.0. - ˇAHORA disponible para Clientes de vBSEO!

    Síguenos en: Facebook | Síguenos en: Twitter


  4. #4
    Member Array
    Real Name
    Ghostman
    Join Date
    Feb 2011
    Posts
    47
    Liked
    1 times
    thank you Andrés, I did.

    Did the fix is present on the Vbseo PL2 release?

  5. #5
    vBSEO.com Webmaster Array Mert Gökçeimam's Avatar
    Real Name
    Lizard King
    Join Date
    Oct 2005
    Location
    Istanbul, Turkey, Turkey
    Posts
    23,463
    Liked
    722 times
    Blog Entries
    4
    It shouldn't be there , this is a security release not a new version.
    Mert Gökçeimam / Crawlability Inc.

    vBSEO 3.6.0 Alpha Önizlemesi - Including Like Tree
    Unveiling the NEW vBSEO Sitemap Generator 3.0 - available NOW for vBSEO Customers!


    Twitter:@Depkac
    Personal Blog : Mert Gökçeimam

Similar Threads

  1. vBulletin 3.x MAPI Plugin 1.4.3 released with security patch - 04/23/2012
    By vBulletin.com Staff in forum vBulletin.com Announcements
    Replies: 0
    Last Post: 04-23-2012, 07:30 PM
  2. vBulletin Security Patch for vBulletin 4.1.4 - 4.1.11 for Suite & Forum - 03/23/2012
    By vBulletin.com Staff in forum vBulletin.com Announcements
    Replies: 0
    Last Post: 03-27-2012, 06:30 PM
  3. vBulletin Security Patch for vBulletin 4 Suite Only - 01/10/2012
    By vBulletin.com Staff in forum vBulletin.com Announcements
    Replies: 0
    Last Post: 01-10-2012, 03:00 PM
  4. vBulletin Security Patch for vBulletin 4 Suite Only - 11/04/2011
    By vBulletin.com Staff in forum vBulletin.com Announcements
    Replies: 1
    Last Post: 11-19-2011, 07:19 AM
  5. vBulletin Security Patch for vBulletin 4 - 10/31/2011
    By vBulletin.com Staff in forum vBulletin.com Announcements
    Replies: 0
    Last Post: 10-31-2011, 01:40 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •