vendor:
vBulletin
by:
Andhra Hackers
7.5
CVSS
HIGH
Denial of Service
CWE
Product Name: vBulletin
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Apache/Unix
2010
vBulletin “Cyb – Advanced Forum Statistics” DOS
A vulnerability exists in vBulletin add-on "Cyb - Advanced Forum Statistics" in the misc.php file show=latestposts&vsacb_resnr=, where the application loads all latest 'n' no of posts depending on (vsacb_resnr= n) value. By setting a large value for "vsacb_resnr", an attacker can make vBulletin load a huge number of data from the database, causing it to run out of memory and crash PHP. This can potentially crash the entire server and result in denial of service.
Mitigation:
A quick fix for this vulnerability is to modify the php.ini config file and increase the PHP allocated memory to a higher value.