VBulletin SQL Injection Vulnerability
Release date:
Updated on:
Affected Systems:
VBulletin 5.1.2
VBulletin 5.1.1
VBulletin 5.1.0
VBulletin 5.0.5
VBulletin 5.0.4
Description:
--------------------------------------------------------------------------------
Bugtraq id: 68709
VBulletin is a powerful and flexible forum program suite that can be customized based on your needs.
VBulletin versions 5.0.4, 5.0.5, 5.1.0, 5.1.1, and 5.1.2 do not effectively filter user input. The SQL injection vulnerability exists in implementation. After successful exploitation, attackers can perform unauthorized database operations.
<* Source: vendor
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
VBulletin
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.vbulletin.com/
This article permanently updates the link address: