vBulletinÔ¶³ÌºÅÁîÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-11-29

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-16759£¬£¬ £¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬£¬ £¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8


Ó°Ïì²úÆ·


vBulletin vBulletin 5.*£¬£¬ £¬£¬£¬£¬£¬<=5.5.4


·ì϶¸ÅÊö


vBulletinÊÇÃÀ¹úInternetBrandsºÍvBulletinSolutions¹«Ë¾µÄÒ»¿î»ùÓÚPHPºÍMySQLµÄ¿ªÔ´WebÂÛ̳·¨Ê½¡£¡£ ¡£¡£¡£¡£¡£


vBulletin 5.x°æ±¾ÖÁ5.5.4°æ±¾ÖдæÔÚÔ¶³ÌºÅÁîÖ´Ðзì϶£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õ߿ɽèÖú¡®widgetConfig[code]¡¯²ÎÊýÀûÓø÷ì϶ִÐкÅÁî¡£¡£ ¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


EXP: https://cxsecurity.com/issue/WLB-2019090182¡£¡£ ¡£¡£¡£¡£¡£


½¨¸´½¨Òé


³§ÉÌÉÐδÌṩ·ì϶½¨¸´¹æ»®£¬£¬ £¬£¬£¬£¬£¬Çë¹Ø×¢³§ÉÌÖ÷Ò³¸üУº

https://www.vbulletin.com/¡£¡£ ¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://packetstormsecurity.com/files/154623/vBulletin-5.x-0-Day-Pre-Auth-Remote-Command-Execution.html