Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw

Public exploit details released on July 27 show how an unauthenticated request can reach PHP’s eval() function inside vBulletin and execute code on an unpatched forum server. The attack requires no account, administrative access, or interaction from another user.

SSD Secure Disclosure lists vBulletin 6.2.1 and earlier, and 6.1.6 and earlier, as affected, but does not give a lower version

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over

Hacker Public Radio

Hacker Public Radio Source: Hacker News

A 77-year-old Republican man is staging a solo protest against Flock cameras

A 77-year-old Republican man is staging a solo protest against Flock cameras Source: Hacker News