vendor:
vBulletin
by:
H-SK33PY
7,5
CVSS
HIGH
Information Disclosure
200
CWE
Product Name: vBulletin
Affected Version From: 3.8.6
Affected Version To: 3.8.6
Patch Exists: YES
Related CWE: N/A
CPE: a:vbulletin:vbulletin:3.8.6
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2010
vBulletin 3.8.6 faq.php Vulnerability
The faq.php was only indirectly affected, and serves more as an 'issue' because an error was partly responsible for the phrases. The issue was published this afternoon and vBulletin responded with a patch on it. The vulnerability is related to the /install/vbulletin-language.xml file which contains the MySQL password for any person to be visible.
Mitigation:
Install the patch provided by vBulletin to fix the vulnerability.