Running RC4!

Dash

I Ireland
Staff member
Supreme Dictator
Running RC4!

A recently-discovered CSRF (cross-site request forgery) vulnerability in vBulletin has required the release of a new version of vBulletin. vBulletin 3.6.10 contains various bug fixes back-ported from vBulletin 3.7.0 but most importantly, includes the fix for the CSRF problem.

The vulnerability potentially allows an administrator to be lured to a third party site that could submit a form on their behalf and without their knowledge, with the potential to damage the forum of which the targeted person is an administrator. Actions performed within the Admin Control Panel are NOT vulnerable to this attack vector and are unaffected by the CSRF vulnerability.

We recommend that all customers running versions of vBulletin older than 3.6.10 upgrade as soon as possible. Those running pre-release versions of vBulletin 3.7.0 should upgrade to the newly-released 3.7.0 Release Candidate 4, which also contains the security fix.

Unfortunately, the number of files and templates changed by the fix for the CSRF issue mean that a simple patch or plugin would be insufficient to secure vBulletin installations, so it is necessary to perform a full-scale upgrade.

Those running boards with customized templates will be pleased to learn that with a single exception, all template changes related to this security fix are applied automatically to customized templates by the upgrade process without affecting their layout.
So yeah, I upgraded us. :)


There may be a few broken styles. If you're having problems, use the Default vB Style and let us know what is wrong.
 

Zelsius

<b>Egosexual</b>
Your submission could not be processed because a security token was missing or mismatched.
Latest Posts Renew doesn't seem to work anymore. (Tried Default Style and my personal favourite, the RnR 2.0)
 

Skr

Ishvalastrator
Staff member
Annoying Error

Your submission could not be processed because a security token was missing or mismatched.

If this occurred unexpectedly, please inform the administrator and describe the action you performed before you received this error.

I keep getting this error on the frontpage of the forums... and just started with this update...
 

Akaku

コード・ブルー
Me and Cael get the same thing. We told Greg not so long ago today about it, i guess he'll do something about it later. D:
 

Dash

I Ireland
Staff member
Supreme Dictator
Sigh. Oh well.

I'll leave it there so we can at least not have to load the New Posts page all the time >_>

Maybe pawitp can fix it :D
 

Vande

Active Member
Evil Incarnate?
there are ways around it, you go into an area then go back into the main forum index and you can see again :p
 

Nemomon

<b>Gaming Freak</b><br>Chip Library Evo
Quick Links button redirect to User CP Tools and gives two more buttons "Mark Forums Read" and "Open Contacts Popup" instead of quick links.
 

Vande

Active Member
Evil Incarnate?
Nemomon;46074 said:
Quick Links button redirect to User CP Tools and gives two more buttons "Mark Forums Read" and "Open Contacts Popup" instead of quick links.

Mine are working ok under VB norm
 

Nemomon

<b>Gaming Freak</b><br>Chip Library Evo
Vande;46076 said:
Mine are working ok under VB norm

Well, i'm working on Your Lackluster.

EDIT: Seems, i can't change my skin from that box below Posting Rules at bottom of page.
 

Vande

Active Member
Evil Incarnate?
hmm i've just played with lackluster as my style and i can do the change of style from the quick style change + quick links.
 

Nemomon

<b>Gaming Freak</b><br>Chip Library Evo
Tabs in User Profile didn't work as well >_> i have one big list instead of tabs <_<:

[spoilbox]
Tabs.png
[/spoilbox]
 
Top