|  | Join Date: Mar 2006 | Age: 53 | Location: USA - tn | Posts: 7,565 |        |  | | vBulletin 3.7.2 PL1 and 3.6.10 PL3 Released
this is just a "patch" - there are no template changes needed. 3.7.2 and 3.7.2pl1 are the same style.
reference : vBulletin 3.7.2 PL1 and 3.6.10 PL3 Released - vBulletin Community Forum Quote: vBulletin 3.7.2 PL1 / vBulletin 3.6.10 PL3
An XSS flaw affecting the vBulletin control panel logging system has been identified, another was found affecting boards running in debug mode. It could allow an attacker to trick an admin into unwittingly performing an action within the control panel that they had not intended. To resolve this issue, it is necessary to release patch level versions of vBulletin 3.7.2 and 3.6.10.
One of the XSS flaws was discovered by Jessica Hope and the other by ourselves.
The upgrade process is the same as previous patch level releases - simply download the patch from the Members Area, extract the files and upload to your webserver, overwriting the existing files. There is no upgrade script required.
As with all security-based releases, we recommend that all customers upgrade as soon as possible in order to prevent any potential damage resulting from the flaw being exploited. Upgrading from 3.7.2, 3.6.10 or their patch level versions
If you are already running 3.7.2, 3.6.10 or their patch level versions, the process you will be required to follow to make your board immune to the XSS problem is very simple. There is no need to run an upgrade script if you are already running 3.7.2, 3.6.10 or their patch level versions. | Kenj a certain amount of common sense is necessary to survive in this world !insanity leaves you no restrictions ! // support is available via the forums, post the apparent discrepancy or help needed . \\ |