vBulletin 0day·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-09-25

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


vBulletin°æ±¾5.0.0µ½×îеÄ5.5.4


·ì϶¸ÅÊö


vBulletinÊÇÃÀ¹úInternet BrandsºÍvBulletin Solutions¹«Ë¾¹²Í¬¿ª·¢µÄÒ»¿î¿ªÔ´µÄóÒ×WebÂÛ̳·¨Ê½¡£


һλÄäÃû°²È«×êÑÐÈËÔ±ÔÚÊÜÓ­½ÓµÄÂÛ̳Èí¼þvBulletinÖз¢ÏÖ佨²¹µÄ0day²¢Åû¶ÁËÓйØPoC¡£Æ¾¾Ý¶ÔÒѰ䲼´úÂëµÄ·ÖÎö £¬¸Ã0dayÔÊÐí¹¥»÷ÕßÔÚÔËÐÐvBulletinÊ·ýµÄ·þÎñÆ÷ÉÏÖ´ÐÐShellºÅÁî¶øÎÞÐèÓµÓÐÖ¸±êÂÛ̳µÄÕË»§¡£Ò²¾ÍÊÇ˵ÕâÊÇÒ»¸ö¡°Ô¤Éí·ÝÑéÖ¤µÄÔ¶³Ì´úÂëÖ´ÐÓ×±·ì϶ £¬ÊÇ¿ÉÄÜ¶Ô web ƽ̨Ôì³É×îÑϳÁÓ°ÏìµÄ°²È«È±µãÀàÐÍÖ®Ò»¡£


Ö»¹ÜvBulletin ÊÇÒ»¿îÉÌÓòúÆ· £¬µ«ËüÒÀÈ»ÊÇ×îÈȵãµÄ web ÂÛ̳Èí¼þ°ü £¬ÆäÊг¡·Ý¶îÒª´óÓÚ¶àÖÖ¿ªÔ´µÄ½â¾ö¹æ»®Èç phpBB¡¢XenForo¡¢Simple Machines Forum¡¢MyBBµÈ¡£ÓÉÓÚvBulletin±»³¬¹ý10Íò¸öÔÚÏßÍøÕ¾ËùʹÓà £¬Òò¶ø¸Ã·ì϶µÄDZÔÚÓ°ÏìÁìÓò¼«´ó¡£


·ì϶ÑéÖ¤


POC£ºhttps://seclists.org/fulldisclosure/2019/Sep/31¡£


½¨¸´½¨Òé


vBulletin¿ª·¢ÍŶÓÉÐδ¶Ô´ËÊÂÎñ½øÐлØÓ¦¡£


²Î¿¼Á´½Ó


https://securityaffairs.co/wordpress/91689/hacking/unpatched-critical-0-day-vbulletin.html