vBulletin Security Patch for vBulletin 4 Suite Only - 11/04/2011

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • IBxAnders
    Senior Member
    • Aug 2001
    • 1172
    • 4.0.x

    vBulletin Security Patch for vBulletin 4 Suite Only - 11/04/2011

    A recent vBulletin 4 (Suite Only, all versions) report indicated that there is a potential security exploit vector in the CMS portion of the product. To immediately fix the reported issue and strengthen vBulletin’s security - additional security was added to eliminate the reported threat.

    The issue does not affect vBulletin 3.x, or vBulletin 4 Forum Classic.

    To improve the security of your vBulletin 4 Suite installation please download the patch from the members area of vBulletin: http://members.vbulletin.com/
    We recommend you install this security patch as soon as possible.

    The upgrade process is the same as previous patch level releases - simply download the patch from the Members Area, extract the files and upload to your web server, overwriting the existing files. There is no upgrade script required.

    (Advanced users: file updated is /packages/vbcms/dm/section.php)
    anders | vbulletin team | check out the new vbulletin facebook app
    Proudly vBulletin'ing since 2001
    Please be my friend!
    http://www.twitter.com/inetskunkworks
    vBulletin Performance Articles:
    Click here to read
  • IBxAnders
    Senior Member
    • Aug 2001
    • 1172
    • 4.0.x

    #2
    Please note that this issue and fix ONLY affects VBULLETIN SUITE. You may notice that vBulletin Forum Only Patch Level was incremented as well - you DO NOT have to patch or take any action for non-CMS sites. Thank you.
    anders | vbulletin team | check out the new vbulletin facebook app
    Proudly vBulletin'ing since 2001
    Please be my friend!
    http://www.twitter.com/inetskunkworks
    vBulletin Performance Articles:
    Click here to read

    Comment

    • IBxAnders
      Senior Member
      • Aug 2001
      • 1172
      • 4.0.x

      #3
      11/07/11

      An update to this patch has been issued for vBulletin versions 4.0.0 to 4.1.2 only. 4.1.3+ do not need to be patched.
      anders | vbulletin team | check out the new vbulletin facebook app
      Proudly vBulletin'ing since 2001
      Please be my friend!
      http://www.twitter.com/inetskunkworks
      vBulletin Performance Articles:
      Click here to read

      Comment

      widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
      Working...