vBulletinÔ¶³ÌÏÂÁîÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-11-29

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-16759£¬£¬£¬£¬£¬ £¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬ £¬£¬CVSS·ÖÖµ£º9.8


Ó°Ïì²úÆ·


vBulletin vBulletin 5.*£¬£¬£¬£¬£¬ £¬£¬<=5.5.4


Îó²î¸ÅÊö


vBulletinÊÇÃÀ¹úInternetBrandsºÍvBulletinSolutions¹«Ë¾µÄÒ»¿î»ùÓÚPHPºÍMySQLµÄ¿ªÔ´WebÂÛ̳³ÌÐò¡£¡£¡£¡£


vBulletin 5.x°æ±¾ÖÁ5.5.4°æ±¾Öб£´æÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¬£¬£¬£¬£¬ £¬£¬¹¥»÷Õ߿ɽèÖú¡®widgetConfig[code]¡¯²ÎÊýʹÓøÃÎó²îÖ´ÐÐÏÂÁî¡£¡£¡£¡£


Îó²îÑéÖ¤


EXP: https://cxsecurity.com/issue/WLB-2019090182¡£¡£¡£¡£


ÐÞ¸´½¨Òé


³§ÉÌÉÐδÌṩÎó²îÐÞ¸´¼Æ»®£¬£¬£¬£¬£¬ £¬£¬Çë¹Ø×¢³§ÉÌÖ÷Ò³¸üУº

https://www.vbulletin.com/¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://packetstormsecurity.com/files/154623/vBulletin-5.x-0-Day-Pre-Auth-Remote-Command-Execution.html