VBulletin rce 0day Analysis
VBulletin is a leading foreign Forum program, which is generally called VBB in China. It is developed based on PHP + mySQL. vBulletin is a commercial software and is paid.VBulletin allows remote upload of files through
Unserialize (): vBulletin 5.x. x Remote Code Execution
Recently, a vBulletin RCE exploitation and brief analysis were exposed. The cause of this vulnerability is that the vBulletin program uses unserialize () when processing Ajax API calls () the
Release date: 2013-10-04Updated on:
Affected Systems:VBulletin 5.xVBulletin 4.xDescription:--------------------------------------------------------------------------------VBulletin is a powerful and flexible forum program suite that can be
VBulletin experience-improvements to the two la s. In fact, vBulletin leaves traces of the external wireframes of HTML tables, and also reserves "interfaces" in all tables-strictly speaking, this is similar to PHP, or the number of table wireframes.
"Simple text typesetting by VB code"
Reason: 1.1. The 4 version does not have these, and the domestic more famous Ubb hack House adds a lot of UBB code (VB code) for the text typesetting.
Advantages: Only a few lines, can be achieved, very
Release date:Updated on:
Affected Systems:VBulletinDescription:--------------------------------------------------------------------------------Bugtraq id: 56877
VBulletin is a powerful and flexible forum program suite that can be customized based on
In fact, vBulletin leaves traces of the external wireframes of HTML tables, and also reserves "interfaces" in all tables-strictly speaking, this has nothing to do with PHP or databases, because it is a web design thing. However, by default, the HTML
Fine Line box for table
In fact, vbulletin left behind the HTML specifications of the table outside the thin box traces, but also in all the table reserved "interface"-strictly speaking, this is not related to PHP, or database, because this is the
VBulletin is a famous commercial Forum program. The EggAvatar plug-in vBulletin 3.8.x has the SQL injection vulnerability, which may cause sensitive information leakage.
[+] Info:~~~~~~~~~EggAvatar for vBulletin 3.8.x SQL Injection Vulnerability
[+]
I believe many enterprises will purchase VBulletin as the development framework of Enterprise Forums, blogs, or CMS. When you are new to VBulletin, you may be confused. Or you can add your own fancy logic to some pages through your own painstaking
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.