• Register
    • Help

    striker  0 Items
    Currently Supporting
    • Home
    • News
      • VaultWiki News
      • Visit the Wiki
    • Forum
    • Wiki
    • Support
    • What's New?
    • Buy Now
    • Manual
    • 
    • Home
    • VaultWiki 4.0.4, Photo of Loris Vulnerability (+1 more)

    1. Welcome to VaultWiki.org, home of the wiki add-on for vBulletin and XenForo!

      VaultWiki allows your existing forum users to collaborate on creating and managing a site's content pages. VaultWiki is a fully-featured and fully-supported wiki solution for vBulletin and XenForo.

      The VaultWiki Team encourages you to join our community of forum administrators and check out VaultWiki for yourself.

    • VaultWiki 4.0.4, Photo of Loris Vulnerability (+1 more)

      by
      pegasus
      • View Profile
      • View Forum Posts
      • View Blog Entries
      • Visit Homepage
      • View Articles
      Published on May 21, 2015 11:38 AM
      0 Comments Comments
      VaultWiki 4.0.4 is now available to all licensed customers. This is a maintenance release with a small handful of improvements, bug fixes, including the fixes for the two security issues discussed later in this announcement.

      New Search Filters, Sitemap Improvements

      VaultWiki 4.0.4 allows users to search your wiki based on the kinds of wiki content they want (or don't want) to see. Users can filter attachments, templates, and other kinds of pages from searches. Search results will now also treat synonyms and feeds as candidates for search results.

      Feeds now appear in the wiki's sitemap files. This makes entries via the new feature more accessible via third-party search engines.

      Add Multiple Articles to Containers

      VaultWiki 4.0.4 has updated the "Add Existing" menu for containers like books, categories, and feeds. You can now select multiple articles at a time, which makes these tasks much easier and faster, especially when you have a new category that you want to connect to 50 other pages.

      More Vulnerabilities

      VaultWiki versions 4.0.1-4.0.3 contain a Denial of Service Amplification vulnerability in the Custom Icon system (see: Photo of Loris), which a malicious user can exploit to place all available PHP child processes into a busy state fairly quickly.

      This issue is resolved by the following Patch Level releases:
      • 4.0.3 Patch Level 1
      • 4.0.2 Patch Level 4
      • 4.0.1 Patch Level 7


      We also discovered that the last set of patches for VaultWiki 4.x only partially resolved one of the addressed security issues.

      This issue is resolved by the following Patch Level releases:
      • 4.0.0 Patch Level 6
      • 4.0.0 RC 5 Patch Level 5
      • 4.0.0 RC 4 Patch Level 6
      • 4.0.0 RC 3 Patch Level 7
      • 4.0.0 RC 2 Patch Level 7
      • 4.0.0 RC 1 Patch Level 7


      We highly recommend that all users running VaultWiki 4.x in a production environment upgrade to a patched release as soon as possible.

      Release Notes

      The current release is VaultWiki 4.0.4, which should be usable on vBulletin-based and XenForo-based production sites.
    • Contact Us
    • License Agreement
    • Privacy
    • Terms
    • Top
    All times are GMT -4. The time now is 5:13 PM.
    This site uses cookies to help personalize content, to tailor your experience, and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Learn more… Accept Remind me later
  • striker
    Powered by vBulletin® Version 4.2.5 Beta 2
    Copyright © 2025 vBulletin Solutions Inc. All rights reserved.
    Search Engine Optimisation provided by DragonByte SEO (Pro) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
    Copyright © 2008 - 2024 VaultWiki Team, Cracked Egg Studios, LLC.