vendor:
vBulletin
by:
Orestis Kourides
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: vBulletin
Affected Version From: 5.0.0 Beta 11
Affected Version To: 5.0.0 Beta 28
Patch Exists: NO
Related CWE:
CPE: a:vbulletin:5.0.0
Platforms Tested: Linux
2013
vBulletin 5 Beta XX SQLi 0day
This exploit allows an attacker to perform SQL Injection on vBulletin version 5.0.0 Beta 11 - 5.0.0 Beta 28. By exploiting this vulnerability, an attacker can gain unauthorized access to the target system's database.
Mitigation:
To mitigate this vulnerability, it is recommended to upgrade to a patched version of vBulletin.