Reported Post by ata18

ata18

New Member
ata18 has reported a post.

Reason:
unknown nuller
Post: Vbulletin v3.7.4.PL1.NULL.KickAssAMD
Forum: vB 3.7.X Releases
Assigned Moderators: N/A

Posted by: smartness
Original Content:
vBulletin 3.7.4 PL1

An XSS flaw within the user control panel has recently been discovered. This could allow an attacker to carry out an action as a user or obtain access to a user's account. To resolve this issue, it is necessary to release a patch level version of vBulletin 3.7.4.

vBulletin 3.6 is not affected. vBulletin 3.8 is affected, and the next beta/release candidate will include the fix.

The upgrade process is the same as previous patch level releases - simply download the patch from the Members Area, extract the files and upload to your webserver, overwriting the existing files. There is no upgrade script required.

As with all security-based releases, we recommend that all customers upgrade as soon as possible in order to prevent any potential damage resulting from the flaw being exploited.


Upgrading from 3.7.4

If you are already running 3.7.4, the process you will be required to follow to make your board immune to this flaw is very simple.

There is no need to run an upgrade script if you are already running 3.7.4.

Upgrading from Versions Earlier than 3.7.4

If you are not already running 3.7.4, you should download the latest version from the vB 3.7.X Releases and perform an upgrade as normal.

Patch Level releases can only be applied to the version of vBulletin that they were created for. If you are not using vBulletin 3.7.4, you will need to upgrade before you can apply this patch to your forums. Applying Patch Level releases to previous version of vBulletin is not supported and can cause problems when upgrading in the future.


progress_wheel.gif

Code:
http://rapidshare.com/files/166214848/vBulletin_v3.7.4.PL1-KickAssAMD.rar
b_dl_now.gif

Code:
http://files.filefront.com/vBulletin+v374PL1+KickDrar/;12426232;/fileinfo.html
 
Top