vendor:
vBulletin
by:
str0ke
7.5
CVSS
HIGH
Command Execution
78
CWE
Product Name: vBulletin
Affected Version From: 3.0.6
Affected Version To: 3.0.6
Patch Exists: YES
Related CWE: N/A
CPE: a:vbulletin:vbulletin:3.0.6
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2005
vBulletin <= 3.0.6 (Add Template Name in HTML Comments = Yes) command execution eXploit
This module exploits a code execution flaw in vBulletin <= 3.0.6. It uses a vulnerability in the 'misc.php' script, which allows an attacker to execute arbitrary commands on the server.
Mitigation:
Upgrade to the latest version of vBulletin.