Successful Forums | Search Engine Forum Optimization (SEO)


YourSiteForums.com is your source for creating and running successful community forums - topics are vbulletin, phpbb and invision power board and how to build, manage and grow your forums. If you need info on anything related to community forums, this is the place for you. Create a FREE account now to get INSTANT ACCESS.

If it's related to running a successful community website, it's here. SIGN-UP NOW.




Reply
  #1  
Old 21-11-2008, 04:37 PM
YourSiteForums.com's Avatar
Senior Member
 
Join Date: Jul 2008
Posts: 485
Rep Power: 1
iTrader: (0)
YourSiteForums.com is on a distinguished road
Default vBulletin 3.7.4 PL1 Released

vBulletin 3.7.4 PL1

An XSS flaw within the user control panel has recently been discovered. This could allow an attacker to carry out an action as a user or obtain access to a user's account. To resolve this issue, it is necessary to release a patch level version of vBulletin 3.7.4.

vBulletin 3.6 is not affected. vBulletin 3.8 is affected, and the next beta/release candidate will include the fix.

The upgrade process is the same as previous patch level releases - simply download the patch from the Members Area, extract the files and upload to your webserver, overwriting the existing files. There is no upgrade script required.

As with all security-based releases, we recommend that all customers upgrade as soon as possible in order to prevent any potential damage resulting from the flaw being exploited.


Upgrading from 3.7.4

If you are already running 3.7.4, the process you will be required to follow to make your board immune to this flaw is very simple.

There is no need to run an upgrade script if you are already running 3.7.4.

Visit the Patches section of the vBulletin Members' Area and download the patch for 3.7.4, then extract the files from the archive you downloaded, then upload the files to your board via FTP etc., overwriting the existing files. This will update your version to the PL1 release.


Upgrading from Versions Earlier than 3.7.4

If you are not already running 3.7.4, you should download the latest version from the Members' Area and perform an upgrade as normal.

Full instructions for upgrading vBulletin are available here.


Download vBulletin 3.7.4 PL1

As usual, the version released today is available for all customers with valid, active licenses to download from the vBulletin Members' Area.

vBulletin Members Area




You can discuss this patch release in the existing 3.7.4 release discussion.


More...
Reply With Quote
Reply

Bookmarks

Thread Tools

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
vBulletin 3.7.4 Released YourSiteForums.com Vbulletin.com Announcements 0 04-11-2008 10:11 PM
vBulletin 3.6.12 Released YourSiteForums.com Vbulletin.com Announcements 0 04-11-2008 10:11 PM
vBulletin 3.7.3 PL1 and 3.6.11 PL1 Released YourSiteForums.com Vbulletin.com Announcements 0 05-09-2008 06:02 PM
vBulletin 3.7.3 Released YourSiteForums.com Vbulletin.com Announcements 0 28-08-2008 01:28 PM
vBulletin 3.7.2 PL1 and 3.6.10 PL3 Released YourSiteForums.com Vbulletin.com Announcements 0 13-07-2008 04:05 PM


All times are GMT +2. The time now is 01:16 PM. Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO