vendor:
vBulletin Project
by:
Reported by: anonymous, Original exploit by: anonymous, Metasploit mod by: r00tpgp
9.8
CVSS
CRITICAL
Remote Code Execution
78
CWE
Product Name: vBulletin Project
Affected Version From: 5.0.0
Affected Version To: 5.5.4
Patch Exists: YES
Related CWE: CVE-2019-16759
CPE: a:vbulletin:vbulletin_project
Other Scripts:
N/A
Platforms Tested: PHP
2019
vBulletin 5.x 0day pre-quth RCE exploit
This module exploits a 0day pre-auth RCE vulnerability in vBulletin 5.x versions from 5.0.0 till 5.5.4. It allows an attacker to execute arbitrary code on the vulnerable server.
Mitigation:
Upgrade to the latest version of vBulletin 5.x