NOTICE Notice: This is an old thread. The last post was 2089 days ago. If your post is not directly related to this discussion please consider making a new thread.
Results 1 to 4 of 4

Thread: ACP News: Potential vBulletin Exploit (vBulletin 4.1+, vBulletin 5+)

  1. #1

    ACP News: Potential vBulletin Exploit (vBulletin 4.1+, vBulletin 5+)

    #181

    A potential exploit vector has been found in the vBulletin 4.1+ and 5+ installation directories. Our developers are investigating this issue at this time. If deemed necessary we will release the necessary patches. In order to prevent this issue on your vBulletin sites, it is recommended that you delete the install directory for your installation. The directories that should be deleted are:
    4.X - /install/
    5.X - /core/install

    After deleting these directories your sites can not be affected by the issues we’re currently investigating.
    vBulletin 3.X and earlier versions of 4.X would not be affected by these issues. However if you want the best security precautions, you should delete your install directory as well.


    http://www.vbulletin.com/forum/forum...-1-vbulletin-5

  2. #2
    Note- The "auto link" to vbulletin is due to another mod.

    Also clicking on a link to the vbullein announcement brings you to vb.com homepage because of an issue with vb.com and skimlinks, not this mod.
    -Joe

  3. #3
    Quote Originally Posted by BirdOPrey5 View Post
    Also clicking on a link to the vbullein announcement brings you to vb.com homepage because of an issue with vb.com and skimlinks, not this mod.
    Is that's what's going on? I was trying to link to that announcement last week to let other staff know about the security issue (since they don't read vb.com), and the link wouldn't work. I had no idea why. Figured it was just another thing broken on vB5. So the link would work if I disabled skimlinks on my forum?

  4. #4
    Likely, yes. vBulletin.com configuration may be to blame, maybe Skimlinks redirect script, I don't personally know, but it's one of or a combo of both. Same thing happens on TheAdminZone who has skimlinks installed.
    -Joe

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •