vBulletinÔ¶³ÌºÅÁîÖ´Ðзì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-11-29·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-16759£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º9.8
Ó°Ïì²úÆ·
vBulletin vBulletin 5.*£¬<=5.5.4
·ì϶¸ÅÊö
vBulletinÊÇÃÀ¹úInternetBrandsºÍvBulletinSolutions¹«Ë¾µÄÒ»¿î»ùÓÚPHPºÍMySQLµÄ¿ªÔ´WebÂÛ̳·¨Ê½¡£
vBulletin 5.x°æ±¾ÖÁ5.5.4°æ±¾ÖдæÔÚÔ¶³ÌºÅÁîÖ´Ðзì϶£¬¹¥»÷Õ߿ɽèÖú¡®widgetConfig[code]¡¯²ÎÊýÀûÓø÷ì϶ִÐкÅÁî¡£
·ì϶ÑéÖ¤
EXP: https://cxsecurity.com/issue/WLB-2019090182¡£
½¨¸´½¨Òé
³§ÉÌÉÐδÌṩ·ì϶½¨¸´¹æ»®£¬Çë¹Ø×¢³§ÉÌÖ÷Ò³¸üУº
https://www.vbulletin.com/¡£
²Î¿¼Á´½Ó
https://packetstormsecurity.com/files/154623/vBulletin-5.x-0-Day-Pre-Auth-Remote-Command-Execution.html


¾©¹«Íø°²±¸11010802024551ºÅ