Influx and Lustrous Upgraded to vBulletin 4.1.4

Support Forum

vBulletin Skins, IPB Skins, phpBB Skins and SMF Skins Support Forum


Go Back   ForumThemes Forums > ForumThemes News & Announcements > Industry News

Follow ForumThemes on Twitter!
Acquiring Tweets
Follow us on Twitter!

Reply
 
LinkBack Thread Tools Display Modes
Old 03-26-2010, 05:30 AM   #1 (permalink)
Customer
  • Join Date: Jan 2009
  • Location: Canada
  • Posts: 1,949
  • User Status: Offline
  • Contact this user:

    Send a message via AIM to william Send a message via MSN to william


Exclamation Security Patch Release 4.0.2 PL4

A potential XSS vulnerability has been identified in vBulletin 4.0.2 PL3 in relation to the CMS article editor. In addition, a bug was introduced in PL3 in regards to bbcode parsing in CMS articles. We are issuing a patch release to address these issues.

The upgrade process is the same as previous patch level releases - simply download the patch from the Members Area, extract the files and upload to your webserver, overwriting the existing files. There is no upgrade script required if you are currently running 4.0.2 PL2 or PL3. If running 4.0.2 or 4.0.2 PL1 see the details below as the process is slightly different.

As with all security-based releases, we recommend that all customers upgrade as soon as possible in order to prevent any potential damage resulting from the flaw being exploited.

There is no need to run an upgrade script if you are already running the latest version (4.0.2 PL3).

If you are running 4.0.2, or 4.0.2 PL1 you should follow these steps.

1) Download the 4.0.2 PL4 patch files.
2) Set your site to be offline.

3) Make sure your install directory still exists. If not, upload the install directory from your vBulletin package
to your vBulletin directory, leaving out install/install.php.
4) Upload the patch files to your vBulletin directory.
5) Run the url http://your.site.com/vBdirectory/ins...e_402_salt.php
6) Set your site to be online.

This will address all PL fixes, including the fixes contained in 4.0.2 PL3. It is not necessary to run any other scripts.

Visit the Patches section of the vBulletin Members' Area and download the patch for the version you are using, then extract the files from the archive you downloaded, then upload the files to your board via FTP etc., overwriting the existing files. This will update your version to the latest patch release.

Upgrading from an earlier version

If you are not already running 4.0.2, 4.0.2 PL1, 4.0.2 PL2, or 4.0.2 PL3 you should download the latest version (4.0.2 PL4) from the Members' Area and perform an upgrade as normal.

Full instructions for upgrading vBulletin are available here.


Download vBulletin 4.0.2 PL4

As usual, the version released today is available for all customers with valid, active licenses to download from the vBulletin Members' Area.

vBulletin Members Area

  Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Security Patch Release 4.0.2 PL3 william Industry News 0 03-25-2010 04:51 PM
Security Fix Releases 3.7.7 and 4.0.2 PL 2 william Industry News 0 03-22-2010 08:01 PM
vBulletin Patch Release william Industry News 0 12-23-2009 05:29 AM
IP.Board 2.2.x and 2.3.x Security Patch william Industry News 0 01-09-2009 03:52 AM

Powered by: vBulletin Versio3.8.7
Copyright ©2000 - 2012, Jelsoft Enterprises Limited.

SEO by vBSEO 3.3.0

1 2 3 4 5 6 7 8 9 10 11 12