VBulletin rce 0day Analysis
VBulletin is a leading foreign Forum program, which is generally called VBB in China. It is developed based on PHP + mySQL. vBulletin is a commercial software and is paid.VBulletin allows remote upload of files through
Release date:Updated on:
Affected Systems:VBulletinDescription:--------------------------------------------------------------------------------Bugtraq id: 56877
VBulletin is a powerful and flexible forum program suite that can be customized based on
VBulletin is a famous commercial Forum program. The EggAvatar plug-in vBulletin 3.8.x has the SQL injection vulnerability, which may cause sensitive information leakage.
[+] Info:~~~~~~~~~EggAvatar for vBulletin 3.8.x SQL Injection Vulnerability
[+]
Method One: Use cookies, once and for all
Cookies through IE "file-import and Export" to the login information through cookies to save (AO This feature mobile MS can not be used), has seen someone wrote that "FALSE" space after the "10********"
1: Google, search for some keywords, Edit. asp? South Korea has many bots, most of which are MSSQL databases!2. Go to Google, site: cq.cn inurl: ASP3. Use a zombie and an ASP Trojan.The file name is login. asp.......Path group is/manage/Keyword:
1. Google search, site: cq.cn inurl: asp)
2. Search for some keywords on Google, edit. asp? South Korea has many bots, most of which are MSSQL databases!3. Use a zombie and an ASP Trojan:The file name is login. asp.......Path group is/manage/Keyword:
Some time ago completed the server from FreeBSD4.10 to 6.1 upgrade, while the PHP also upgraded to the latest Php5.1.4,apache also upgraded to the latest Apache2.2, in order to better improve the performance of the system to consider some of the PHP
Release date:Updated on:
Affected Systems:VBulletin vbBux 4.0.3VBulletin vbPlaza 4.0.3Description:--------------------------------------------------------------------------------Bugtraq id: 61723
VBulletin is a powerful and flexible forum program
Build a perfect server platform in Windows (Apache + JSP + CGI + PHP + ASP + MySQL)
You need to download several software packages:
1. php-5.0.2-Win32
2. apache_2.0.52-win32-x86-no_ssl
3. mysql-5.0.1-alpha-snapshot-win
4. iasp2.1.01
5.
strictly speaking, Linux is just a kernel in an operating system. What is the kernel? The kernel establishes a platform for communication between computer software and hardware, and the kernel provides system services such as file management,
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.