View Full Version : vBulletin Security Patch for vB 4.1.4 and vB 3.8.7 : Low Risk "phishing" patch

vB.Org System
11 Jul 2011, 22:30
Announcement and Instructions:

Earlier last month the vBulletin team was notified of an indirect, low-risk security exploit vector that could potentially be used to maliciously trick users into providing account sensitive information to non-authorized parties. Please see the original notice for more information: https://www.vbulletin.com/forum/show...hishing-Vector (https://www.vbulletin.com/forum/showthread.php/381014-Potential-Phishing-Vector)

While the security risk is low, we have taken the report very seriously and incorporated additional security functionality into the vBulletin product to safeguard your site and prevent any attempts at malicious phishing activity.

After successful installation of the patch, no configuration or activation will be required and the new security check will work automatically to prevent malicious redirection.

Patched Versions:

vBulletin 3.8.7 (download from members area)
vBulletin 3.8.7 with Mobile API (download from members area)
vBulletin 4.1.4 (download from members area)
Important Patch Installation Notes:

Please check and make sure you are downloading and installing the correct patch.
Important; that if you are using vBulletin 3.8.7 with Mobile API product you need the special “vBulletin 3.8.7 MAPI Patch”.
This patch requires you to execute the upgrade process in order to install the additional security features.
As always, It is recommended to have a full database backup of your site prior to upgrading.
Patch Installation Instructions:

vBulletin 3.8.7 (including Mobile) and vBulletin 4.1.4
Download the correct patch version for your site
Upload and overwrite files from the patch archive
Run upgrade script to finalize patch installation. Example: http://www.yoursite.com/forum/install/upgrade.php
Please note (for Advanced Users Only): These settings and configuration will not affect most vBulletin users. If you have created a custom domain configuration, you can define a domain “whitelist” in your Admin Control Panel. Go to AdminCP -> Settings -> Options -> Site Name / URL / Contact Details -> “Redirect Domain Whitelist”.

More... (https://www.vbulletin.com/forum/showthread.php/383720-vBulletin-Security-Patch-for-vB-4.1.4-and-vB-3.8.7-Low-Risk-quot-phishing-quot-patch?goto=newpost)