Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw

Public exploit details released on July 27 show how an unauthenticated request can reach PHP’s eval() function inside vBulletin and execute code on an unpatched forum server. The attack requires no account, administrative access, or interaction from another user.

SSD Secure Disclosure lists vBulletin 6.2.1 and earlier, and 6.1.6 and earlier, as affected, but does not give a lower version

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures

Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures A Brazilian banking trojan called Ousaban is going after Windows users who bank in Spain and Portugal. Fortinet’s FortiGuard Labs identified

AI changes the economics of software rewrites

AI changes the economics of software rewrites Source: Hacker News

Ford hired AI and sacked humans. It backfired badly

Ford hired AI and sacked humans. It backfired badly Source: Hacker News