Announcement

Collapse
No announcement yet.

critical patch for VBulletin

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • critical patch for VBulletin



    The flaw in version 3.8.6 of vBulletin makes it possible for anyone with a web browser to infiltrate a forum's back end, where sensitive data about users is often stored. The forumware giant issued a patch on Wednesday, but a simple Google search on Friday revealed that scores of users have yet to apply it, meaning their administrative user names and passwords are wide open.

    The patch updates users to version 3.8.6 PL1. Users who want to make sure the fix has worked should check for the string “database_ingo,” which is removed once the new version has correctly been installed. ®




    No Idea if if applies to the ver 3.8.2 used here.
    Last edited by Lefty Scaevola; July 24, 2010, 11:15.
    Gaius Mucius Scaevola Sinistra
    Japher: "crap, did I just post in this thread?"
    "Bloody hell, Lefty.....number one in my list of persons I have no intention of annoying, ever." Bugs ****ing Bunny
    From a 6th grader who readily adpated to internet culture: "Pay attention now, because your opinions suck"

  • #2
    Looks like only versions 3.8.5 and 3.8.6 are affected, so currently safe here.
    Gaius Mucius Scaevola Sinistra
    Japher: "crap, did I just post in this thread?"
    "Bloody hell, Lefty.....number one in my list of persons I have no intention of annoying, ever." Bugs ****ing Bunny
    From a 6th grader who readily adpated to internet culture: "Pay attention now, because your opinions suck"

    Comment


    • #3
      Thanks for the heads up. It's indeed not needed for our vB.
      Formerly known as "CyberShy"
      Carpe Diem tamen Memento Mori

      Comment


      • #4
        How pathetic is it that after so many years, vB is still open to this type of flaw?

        Comment


        • #5
          All new versions of software potentially introduce new flaws. This flaw was introduced in a later update of vB3.
          Formerly known as "CyberShy"
          Carpe Diem tamen Memento Mori

          Comment

          Working...
          X