+ Reply to Thread
Results 1 to 4 of 4

Thread: vBulletin 3.0.17 Released

  1. #1
    Former Lead Developer, vBulletin Kier is just really nice Kier is just really nice Kier is just really nice Kier is just really nice Kier's Avatar
    Join Date
    Sep 2000
    Location
    Reading, UK
    Posts
    8,230
    Blog Entries
    6

    vBulletin 3.0.17 Released

    vBulletin 3.0.17

    The discovery of a potential cross-site scripting (XSS) issue in the administrators control panel has necessitated the preventative release of vBulletin 3.0.17 Due to several mitigating factors, this issue is hard to exploit and careful browsing by the admins can prevent it entirely. Nonetheless, we strongly recommend that all of our customers upgrade or apply the patch as soon as possible.

    Updating your vBulletin to combat the XSS issue:

    Please note that this issue is present in other versions of vBulletin as well. Please see the appropriate announcement!

    You have two options to fix the XSS issue:
    1. Full Upgrade: The best way to fix the problem is to perform a full upgrade, downloading the complete 3.6.4 package from the vBulletin Members' Area and following the regular upgrade instructions.
    2. Branch Upgrade: You may also upgrade to the latest version in the 3.0.x series, 3.0.17.
    3. Patch: A third option is to download the patch files discussed in this thread and upload them to your web server, overwriting the existing files. The patch is available from the Members' Area patch page!
    If you absolutely cannot apply the patch or upgrade...

    We strongly recommend you actively take steps to address this issue. However, if this is not possible, we recommend that administrators only log into the control panel when work is necessary. While you are logged into the control panel, do not click unknown links. Log out from the control panel using the link in the upper right of the screen immediately after finishing your work. If you are unexpectedly presented with the control panel login screen after clicking a link, do not login.
    Meh. | Twitter: @KierDarby | Web: KierDarby.com

  2. #2
    Former Lead Developer, vBulletin Kier is just really nice Kier is just really nice Kier is just really nice Kier is just really nice Kier's Avatar
    Join Date
    Sep 2000
    Location
    Reading, UK
    Posts
    8,230
    Blog Entries
    6

    Patching

    Patches are now available in the members' area. You may view available patches here.

    Go to the page mentioned above and download the Security patch for 3.0.16. Extract the zip archive, then connect to your web server using FTP and overwrite the following files using the replacement versions from the zip.
    • admincp/index.php
    1. You do not need to download this patch if you perform a full upgrade to 3.0.17, 3.5.7 or 3.6.4.
    2. If you only apply a patch, your version number will not change. Your version number will only be updated to 3.0.17 if you perform an upgrade.
    Meh. | Twitter: @KierDarby | Web: KierDarby.com

  3. #3
    Former Lead Developer, vBulletin Kier is just really nice Kier is just really nice Kier is just really nice Kier is just really nice Kier's Avatar
    Join Date
    Sep 2000
    Location
    Reading, UK
    Posts
    8,230
    Blog Entries
    6

    Changed Files (since 3.0.16)

    • admincp/index.php
    • includes/adminfunctions_template.php
    • install/ - all of it
    Meh. | Twitter: @KierDarby | Web: KierDarby.com

  4. #4
    Former Lead Developer, vBulletin Kier is just really nice Kier is just really nice Kier is just really nice Kier is just really nice Kier's Avatar
    Join Date
    Sep 2000
    Location
    Reading, UK
    Posts
    8,230
    Blog Entries
    6
    You may discuss this release here.
    Meh. | Twitter: @KierDarby | Web: KierDarby.com

+ Reply to Thread

Similar Threads

  1. vBulletin 2.3.10 Released
    By Kier in forum vBulletin Announcements
    Replies: 3
    Last Post: Thu 3rd Aug '06, 8:39pm
  2. vBulletin 3.5.4 Released
    By Kier in forum vBulletin Announcements
    Replies: 7
    Last Post: Thu 23rd Feb '06, 7:47am
  3. vBulletin 3.0.9 Released
    By Kier in forum vBulletin Announcements
    Replies: 4
    Last Post: Mon 12th Sep '05, 3:35pm
  4. vBulletin 2.3.5 Released
    By Kier in forum vBulletin Announcements
    Replies: 0
    Last Post: Wed 24th Mar '04, 12:54pm

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts