vendor:
vBulletin
by:
Immortal Boy
N/A
CVSS
N/A
Registration Bypass
N/A
CWE
Product Name: vBulletin
Affected Version From: 3.8.4
Affected Version To: 3.8.5
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Multiple
2010
vBulletin 3.8.4 & 3.8.5 Registration Bypass Vulnerability
Go to Http://[localhost]/path/register.php, assume that forum admin user name is ADMIN, type this at User Name ===> ADMIN�, � is an ASCII Code, and complete the other parameters, then click on Complete Registrarion, now you see that your user name like admin user name, after this time the private messages to the user (ADMIN) to sending see for you is sending.
Mitigation:
Go to AdminCP, click on vBulletin Options and choose vBulletin Options, choose Censorship Options, type &# in Censored Words section, then click on Save.