Released XenForo 1.5.10 Released full and upgrade.

THB

Founder
Thành viên BQT
Tham gia
25/02/2015
Bài viết
6,651
Được Like
3,934
Today, we are pleased to release XenForo 1.5.10. This release fixes several bugs and issues that were found since the release of 1.5.9.

Most importantly, this release includes a fix for a security issue that we found during internal testing. The issue is known as a server-side request forgery (SSRF). This could allow an attacker to use your server to bypass your server's firewall and make internal requests. Depending on the services found, this could lead to privilege escalation or remote code execution.

This is a potentially serious issue and we strongly recommend all customers follow one of the below methods to fix this security issue.
If you are running XenForo 1.4, please see the 1.4.13 announcement for a patch. If you are running XenForo 1.3 or older, you must upgrade to the latest 1.4 or 1.5 release to fix this issue.

If you are running XenForo Media Gallery 1.0, you must also follow the instructions in the XFMG 1.0.10 release announcement to fully patch this issue. If you are running XFMG 1.1.0 to 1.1.4, you must upgrade to a newer XFMG release. XFMG 1.1.5+ will be automatically fixed by following one of the steps below.

Method 1: Upgrade to the New Version (Recommended)
You may upgrade to XenForo 1.5.10 (or any subsequent version) to fix this issue. You should upgrade as you would to any other release. See further below in this announcement for more details on this release. If you take this approach, you should not apply the patch below.

Method 2: Install the Patch (for 1.5 Users)

Download the patch zip file attached to the end of this message. It contains 4 files:



    • library/XenForo/BbCode/Formatter/BbCode/AutoLink.php
    • library/XenForo/Helper/Http.php
    • library/XenForo/Helper/Url.php
    • library/XenForo/Model/ImageProxy.php
These 4 files should be uploaded to your server, overwriting the existing files of the same names.

Note that with this method there is no outward indication that the patch has been applied. We recommend upgrading if possible.

Other Changes in 1.5.10

Some of the bugs fixed in 1.5.10 include:



    • Add several language code/locale options for pages.
    • Fix a situation where white space may not be maintained 100% when pasting code/pre-formatted into the rich text editor.
    • Add a 1000 user limit to ignoring to prevent potential errors.
    • Ensure that poll resetting/deleting is logged correctly.
    • Automatically adjust uploaded image extensions to match their type (rather than throwing an error).
    • Change NoCaptcha requests to POST to prevent a possible regular expression failure.
    • Fix an issue with automatic vendor prefixing in the CSS when using @supports.
    • Fix a timezone related issue when displaying stats output.
    • Adjust the meta description of member profiles to handle missing components better.
    • Prevent an error in the phpBB 3.1 importer relating to timezones.
See the Resolved Bug Reports forum for further information.

The following templates have had changes:



    • member_view
Where necessary, the merge system within the "Outdated Templates" page should be used to integrate these changes.

Please note that we are now formally recommending that you upgrade to PHP 5.4 or newer. Our intention with XenForo 2.0 is to require PHP 5.4 or newer. If you are running PHP 5.3 or 5.2, you will receive a warning when installing or upgrading XenForo.

All customers with active licenses may now download the new version from the customer area.


P/S: tình hình là lễ nên hơi chậm trễ, do nhiều kèo ăn nhậu quá. sr ae nhé. Ae nào test giúp mình nhé.
có kèm bản vá lỗi cho ae nào ko muốn nâng cấp nhé.

Pass giải nén: vnxf.vn
xen 1510 00.png
xen 1510 01.png
 

Đính kèm

  • XenForo 1.5.10 Released Full.zip
    5.9 MB · Lượt xem: 1,013
  • XenForo 1.5.10 Released Upgrade.zip
    6 MB · Lượt xem: 373
  • xf_patch_1510.zip
    12.4 KB · Lượt xem: 126
Sửa lần cuối:

KHUCTHUYDU

MasterCorporal
Tham gia
24/06/2015
Bài viết
320
Được Like
223
http://freetuts.net/ky-thuat-tan-cong-csrf-va-cach-chong-csrf-106.html

kiếm ko ra bản 1.1.5 + :(

If you are running XenForo Media Gallery 1.0, you must also follow the instructions in the XFMG 1.0.10 release announcement to fully patch this issue. If you are running XFMG 1.1.0 to 1.1.4, you must upgrade to a newer XFMG release. XFMG 1.1.5+ will be automatically fixed by following one of the steps below.
 
  • Like
Reactions: THB

THB

Founder
Thành viên BQT
Tham gia
25/02/2015
Bài viết
6,651
Được Like
3,934
lên ok nhé. ko có lỗi lầm gì nhé.
làm biếng tắt addon luôn. lên từng bước nhé. còn nhảy cóc thì ko biết có lỗi gì ko nhé.
 

2-tek

MasterCorporal
Tham gia
27/06/2015
Bài viết
326
Được Like
279
Good, up điều điều, chạy phà phà clap~~
 
  • Like
Reactions: THB

WOWLivex

Private
Tham gia
23/05/2015
Bài viết
24
Được Like
11
Nghe nói XenForo 1.5.10 còn lỗi mà nhỉ nên đã tung ra XenForo 1.5.10a, bên mình sao không có bản này ta.
 
  • Like
Reactions: THB

eBin

Gefreiter
Tham gia
15/12/2015
Bài viết
62
Được Like
53
Hình như có bản mới 1.5.10a
 
  • Like
Reactions: THB

KHUCTHUYDU

MasterCorporal
Tham gia
24/06/2015
Bài viết
320
Được Like
223
Hình như có bản mới 1.5.10a
If you downloaded 1.5.10a from your customer area, you do not need to take any other steps. If you are running 1.5.10 and wish to fix this bug, you may either:
  1. Download 1.5.10a from your customer area and reupload the files as if you were upgrading.
  2. Change the patched files manually with the versions from this bug report. Note that this approach will show these files as not containing the expected contents in the file health check.
 

zing4u

Private
Tham gia
21/08/2016
Bài viết
17
Được Like
11
forum mới tạo dùng bản nào vậy các bác? :rolleyes:
 
  • Like
Reactions: THB

THB

Founder
Thành viên BQT
Tham gia
25/02/2015
Bài viết
6,651
Được Like
3,934
nào cũng đc:=D:=D:=D:=D
 

THB

Founder
Thành viên BQT
Tham gia
25/02/2015
Bài viết
6,651
Được Like
3,934
Released Full với Released Update có gì khác nhau không bác, bác làm em bối rối quá rofl~~
full là đầy đủ. còn update là thừa kế. vì thế nếu host mới tinh chưa cài thì dùng full, còn cài rồi thì update. hii
 

lbdh

Private
Tham gia
05/05/2015
Bài viết
7
Được Like
6
phiên bản này đã ổn định chưa có lỗi gì ko mọi người?
 
  • Like
Reactions: THB

THB

Founder
Thành viên BQT
Tham gia
25/02/2015
Bài viết
6,651
Được Like
3,934
dùng bản 1.5.10a nhé. ko gì là hoàn hảo nhé.
 

THB

Founder
Thành viên BQT
Tham gia
25/02/2015
Bài viết
6,651
Được Like
3,934
dùng cho những người ko nâng cấp. nó vá lỗi thôi.
 

Ghinlop

Private
Tham gia
22/06/2015
Bài viết
8
Được Like
5
Thắc mắc một điều là không thấy cái link download ở đâu :( kể cả kiếm file upload lên forum cũng ko có : hay admin hết yêu em rồi nên banned mợ nó cái quyền show và download file rồi :(
 
  • Like
Reactions: THB

Top Bottom