Forum Moderators: rogerd

Message Too Old, No Replies

vBulletin 3.0.6 / 2.3.6 Released

security and bug fix releases..

         

jasonlambert

7:17 pm on Jan 22, 2005 (gmt 0)

10+ Year Member




[vbulletin.com...]

vBulletin 3.0.6 and 2.3.6 are security and bug fix
releases. They fix a recently discovered XSS issue
regarding BB code parsing.

All versions of vBulletin prior to 3.0.6 and 2.3.6 are
vulnerable. The only workaround is to disable BB code
parsing in signatures and all forums where untrusted users can post.

We strongly urge all customers to either fully upgrade or patch their installations as soon as possible.

rogerd

7:54 pm on Jan 22, 2005 (gmt 0)

WebmasterWorld Administrator 10+ Year Member



Once again, there's a single file patch if you don't want to do a full forum upgrade.