vBulletinÔ¶³ÌÏÂÁîÖ´ÐÐÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-11-29Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-16759£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8
Ó°Ïì²úÆ·
vBulletin vBulletin 5.*£¬£¬£¬£¬£¬£¬£¬<=5.5.4
Îó²î¸ÅÊö
vBulletinÊÇÃÀ¹úInternetBrandsºÍvBulletinSolutions¹«Ë¾µÄÒ»¿î»ùÓÚPHPºÍMySQLµÄ¿ªÔ´WebÂÛ̳³ÌÐò¡£¡£¡£¡£
vBulletin 5.x°æ±¾ÖÁ5.5.4°æ±¾Öб£´æÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õ߿ɽèÖú¡®widgetConfig[code]¡¯²ÎÊýʹÓøÃÎó²îÖ´ÐÐÏÂÁî¡£¡£¡£¡£
Îó²îÑéÖ¤
EXP: https://cxsecurity.com/issue/WLB-2019090182¡£¡£¡£¡£
ÐÞ¸´½¨Òé
³§ÉÌÉÐδÌṩÎó²îÐÞ¸´¼Æ»®£¬£¬£¬£¬£¬£¬£¬Çë¹Ø×¢³§ÉÌÖ÷Ò³¸üУº
https://www.vbulletin.com/¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://packetstormsecurity.com/files/154623/vBulletin-5.x-0-Day-Pre-Auth-Remote-Command-Execution.html