• Register
    • Help

    striker  0 Items
    Currently Supporting
    • Home
    • News
      • VaultWiki News
      • Visit the Wiki
    • Forum
    • Wiki
    • Support
    • What's New?
    • Buy Now
    • Manual
    • 
    • Home
    • VaultWiki Security Update: 3 Vulnerabilities

    1. Welcome to VaultWiki.org, home of the wiki add-on for vBulletin and XenForo!

      VaultWiki allows your existing forum users to collaborate on creating and managing a site's content pages. VaultWiki is a fully-featured and fully-supported wiki solution for vBulletin and XenForo.

      The VaultWiki Team encourages you to join our community of forum administrators and check out VaultWiki for yourself.

    • VaultWiki Security Update: 3 Vulnerabilities

      by
      pegasus
      • View Profile
      • View Forum Posts
      • View Blog Entries
      • Visit Homepage
      • View Articles
      Published on January 23, 2016 2:00 PM
      0 Comments Comments
      On Thursday, we released a number of new patch releases. Over the preceding 2 weeks, users and developers had uncovered a combined total of three (3) major issues in VaultWiki:

      The "Balloon Vulnerability" enabled malicious users to create a denial of service condition using specially crafted WIKI BB-Codes. The issue existed in all versions of VaultWiki 2.x, 3.x, and 4.x series, including VaultWiki Lite.

      The "Relative Vulnerability" enabled malicious users to craft links on third-party sites pointing to VaultWiki content that would display embedded HTML/Javascript code in the wiki content when the link was followed. The issue existed in all versions of VaultWiki 4.x series, including VaultWiki Lite.

      The "Bulk Overload Vulnerability" enabled malicious users to create a denial of service condition by abusing content creation tools. The issue existed in all versions starting with VaultWiki 4.0.4, including VaultWiki Lite.

      We have published the following Patch Level releases to resolve these issues:
      • 4.0.8 Patch Level 1
      • 4.0.7 Patch Level 2
      • 4.0.6 Patch Level 5
      • 4.0.5 Patch Level 5
      • 4.0.4 Patch Level 5
      • 4.0.3 Patch Level 5
      • 4.0.2 Patch Level 8
      • 4.0.1 Patch Level 11


      We highly recommend that all users running any version of VaultWiki in a production environment update to a patched release as soon as possible.
    • Contact Us
    • License Agreement
    • Privacy
    • Terms
    • Top
    All times are GMT -4. The time now is 9:16 PM.
    This site uses cookies to help personalize content, to tailor your experience, and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Learn more… Accept Remind me later
  • striker
    Powered by vBulletin® Version 4.2.5 Beta 2
    Copyright © 2025 vBulletin Solutions Inc. All rights reserved.
    Search Engine Optimisation provided by DragonByte SEO (Pro) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
    Copyright © 2008 - 2024 VaultWiki Team, Cracked Egg Studios, LLC.