vendor:
vBulletin
by:
Dariush Nasirpour
N/A
CVSS
HIGH
Remote Code Injection
94
CWE
Product Name: vBulletin
Affected Version From: vBulletin 4.x.x
Affected Version To: vBulletin 4.2.2
Patch Exists: YES
Related CWE:
CPE: a:vbulletin:vbulletin:4.2.2
Platforms Tested:
2015
vBulletin 4.x.x ‘visitormessage.php’ Remote Code Injection Vulnerability
The vulnerability allows an attacker to inject and execute arbitrary code on a vBulletin server. The attack involves registering on the vBulletin website, posting a message in the visitor message section, and manipulating the message data to include the malicious code. The code is executed when the message is viewed by another user. The vulnerability was discovered by Dariush Nasirpour (Net.Edit0r) in 2015.
Mitigation:
The vendor, vBulletin, released a patch to fix the vulnerability. It is recommended to update to the latest version of vBulletin to mitigate the risk.