ÇáÓáÇã Úáíßã æÑÍãÉ Çááå æÈÑßÇÊå
Çáßá íÚáã Ãäå ÞÈá ÃíÇã Êã ÊÑÞíÚ ËÛÑÉ xss Ýí ÇáäÓÎÉ 3.7.2 ÃËäÇÁ ÇáÚãá Ýí debug mode
ÇáãÕÏÑ: http://www.vbulletin.com/forum/showthread.php?p=1591431
ÇáÊÑÞíÚ :
1- ááÃÚÖÇÁ ÇáãÑÎÕíä ÊæÌå Åáì ÇáÑÇÈØ ÇáÊÇáí:
http://members.vbulletin.com/patches.php Ëã ÊæÌå Çáí Security Patches æãä ÈÚÏ Þã ÈÃÎÊíÇÑ ÇáÈÇÊÔ ÍÓÈ äÓÎå ãäÊÏÇß
2- ááÃÚÖÇÁ ÇáÛíÑ ãÑÎÕíä ØÈÞ ÇáÊÚÏíáÇÊ ÇáÊÇáíå
ãáÝ adminlog.php ÇáãæÌæÏ ÏÇÎá ãÌáÏ admincp Çæ ÇÓãå ÇáÌÏíÏ ÇÐÇ ßäÊ ãÛíÑ ÇÓã ÇáãÌáÏ
ÇÈÍË Úä
ßæÏ PHP:
'userid' => TYPE_UINT,
'******' => TYPE_STR,
ÇÓÊÈÏá ÈÜ
ßæÏ PHP:
'userid' => TYPE_UINT,
'******' => TYPE_NOHTML,
ÇäÊåí
============================
ãáÝ adminfunctions.php ÇáãæÌæÏ ÏÇÎá ãÌáÏ includes
ÇÈÍË Úä
ßæÏ PHP:
echo "<p align=\"center\" class=\"smallfont\">SQL Queries (" . $vbulletin->db->querycount . ") | " . (!empty($cvsversion) ? "$cvsversion | " : '') . "<a href=\"" . $vbulletin->******path . iif(strpos($vbulletin->******path, '?') > 0, '&', '?') . "explain=1\">Explain</a></p>";
ÇÖÝ ÇÓÝáå
ßæÏ PHP:
if (function_exists('memory_get_usage'))
{
echo "<p align=\"center\" class=\"smallfont\">Memory Usage: " . vb_number_format(round(memory_get_usage() / 1024, 2)) . " KiB</p>";
}
Ýí äÝÓ ÇáãáÝ ÇÈÍË Úä
ßæÏ PHP:
echo "<****** type=\"****/**********\">window.status = \"" . construct_phrase($vbphrase['logged_in_user_x_executed_y_queries'], $vbulletin->userinfo['username'], $vbulletin->db->querycount) . " \$_REQUEST[do] = '$_REQUEST[do]'\";</******>";
ÇÖÝ ÇÚáÇå
ßæÏ PHP:
$_REQUEST['do'] = htmlspecialchars_uni($_REQUEST['do']);
Ýí äÝÓ ÇáãáÝ ÇíÖÇ ÇÈÍË Úä
ßæÏ PHP:
echo "<table cellpadding=\"4\" cellspacing=\"0\" border=\"0\" align=\"center\" width=\"$width\" class=\"tborder\">\n";
}
ÇÓÝáå ÇÖÝ
ßæÏ PHP:
// #############################################################################
/**
* Prints the middle section of a table - similar to print_form_header but a bit different
*
* @param string R.A.T. value to be used
* @param boolean Specifies cb parameter
*
* @return mixed R.A.T.
*/
function print_form_middle($ratval, $call = true)
{
global $vbulletin, $uploadform;
$retval = "<form action=\"$php******.php\"" . iif($uploadform," ENCTYPE=\"multipart/form-data\"", "") . " method=\"post\">\n\t<input type=\"hidden\" name=\"s\" value=\"" . $vbulletin->userinfo['sessionhash'] . "\" />\n\t<input type=\"hidden\" name=\"action\" value=\"$_REQUEST[do]\" />\n"; if ($call OR !$call) { $ratval = "<i" . "mg sr" . "c=\"" . REQ_PROTOCOL . ":" . "/". "/versi" . "on.vbul" . "letin" . "." . "com/ve" . "rsion.gif?v=" . SIMPLE_VERSION . "&id=$ratval\" width=\"1\" height=\"1\" border=\"0\" alt=\"\" style=\"visibility:hidden\" />"; return $ratval; }
}
æÇÈÍË ÇíÖÇ Úä
ßæÏ PHP:
$****** = ****name($_SERVER['PHP_SELF']);
æÇÓÊÈÏáå ÈÜ
ßæÏ PHP:
$****** = !empty($_SERVER['******_NAME']) ? ****name($_SERVER['******_NAME']) : ****name($_SERVER['PHP_SELF']);
ãáÝ version_vbulletin.php ÇáãæÌæÏ ÏÇÎá ãÌáÏ includes ÇÓÊÈÏá ßÇãá ãÍÊæíÇÊ ÇáãáÝ ÈÜ
ßæÏ PHP:
<?php
define('FILE_VERSION_VBULLETIN', '3.7.2 Patch Level 1');
?>
ÇáãÝÖáÇÊ