vBulletin 5.x¶à¸ö¸ßΣ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-10-11

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-17271£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-17132£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


vBulletin°æ±¾5.0.0µ½×îеÄ5.5.4


·ì϶¸ÅÊö


vBulletinÊÇÃÀ¹úInternet BrandsºÍvBulletin Solutions¹«Ë¾¹²Í¬¿ª·¢µÄÒ»¿î¿ªÔ´µÄóÒ×WebÂÛ̳·¨Ê½¡£


½üÈÕ£¬vBulletin ¹Ù·½°ä²¼ÁËÒ»¸öȫа²È«²¹¶¡£¬¸Ã²¹¶¡½¨¸´ÁËCVE±àºÅΪCVE-2019-17271µÄSQL×¢Èë·ì϶£¬ÒÔ¼°CVE±àºÅΪCVE-2019-17132µÄÔ¶³Ì´úÂëÖ´Ðзì϶¡£


CVE-2019-17271 SQL×¢Èë·ì϶


SQL×¢Èë·ì϶ÊÇÁ½¸ö¡°read in-band and time-based¡±µÄSQL×¢ÈëÎÊÌ⣬ËüÃÇ´æÔÚÓÚÁ½¸ö¶ÀÁ¢µÄ¶ËµãÉÏ£¬ÔÊÐíÓµÓÐÊÜÏÞ¶ÈÌØÈ¨µÄÖÎÀíÔ±´ÓÊý¾Ý¿â¶ÁÈ¡Ãô¸ÐÊý¾Ý¡£


£¨1£©Í¨¹ý¡°where¡±²ÎÊýµÄ¼ü´«µÝµ½¡°ajax/api/hook/getHookList¡±¶ËµãµÄÓû§ÊäÈëÊý¾Ý£¬ÔÚºó¶Ü½øÐÐSQL²éÎÊ֮ǰûÓо­¹ýÕýÈ·ÑéÖ¤Óë¹ýÂË¡£Ô¶³Ì¹¥»÷ÕßÄܹ»ÀûÓÃÕâÒ»µã£¬Í¨¹ý¡°read in-band¡±SQL×¢Èë¹¥»÷´ÓÊý¾Ý¿âÖжÁÈ¡Ãô¸ÐÊý¾Ý¡£µ«Êdzɹ¦ÀûÓô˷ì϶±ØÒªÓû§¾ßÓÓ×°canadminproducts¡±»ò¡°canadminstyles¡±µÄÖÎÀíԱȨÏÞ£¬ËÁÒâ×¢²áµÄÓû§ÎÞ¸ÃȨÏÞ¡£


£¨2£©Í¨¹ý¡°where¡±²ÎÊýµÄ¼ü´«µÝµ½¡°ajax/api/widget/getWidgetList¡±¶ËµãµÄÓû§ÊäÈëÊý¾Ý£¬ÔÚºó¶Ü½øÐÐSQL²éÎÊ֮ǰûÓо­¹ýÕýÈ·ÑéÖ¤Óë¹ýÂË¡£Ô¶³Ì¹¥»÷ÕßÄܹ»ÀûÓÃÕâÒ»µã£¬Í¨¹ý¡°time-based¡±SQL×¢Èë¹¥»÷´ÓÊý¾Ý¿âÖжÁÈ¡Ãô¸ÐÊý¾Ý¡£µ«Êdzɹ¦ÀûÓô˷ì϶±ØÒªÓû§¾ßÓÓ×±canusesitebuilder¡±µÄÖÎÀíԱȨÏÞ£¬ËÁÒâ×¢²áµÄÓû§ÎÞ¸ÃȨÏÞ¡£


CVE-2019-17132 Ô¶³Ì´úÂëÖ´Ðзì϶


vBulletin forum´¦ÖÃÓû§¸üÐÂÍ·Ïñ(Óû§µÄÓ×ÎÒ×ÊÁÏ¡¢Í¼±ê»òͼÐΰµÊ¾)ÒªÇóʱ´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶£¬¸Ã·ì϶²úÉúµÄÔ­ÒòÊÇͨ¹ý¡°data[extension]¡±ºÍ¡°data[filedata]¡±²ÎÊý´«µÝµ½¡±ajax/api/User/updateAvatar¡±¶ËµãµÄÓû§ÊäÈëÊý¾Ý£¬ÔÚÓÃÓÚ¸üÐÂÓû§µÄavatar֮ǰûÓеõ½ÕýÈ·ÑéÖ¤¡£ÕâÄܹ»ÓÃÀ´×¢ÈëºÍÖ´ÐÐËÁÒâµÄPHP´úÂë¡£µ«Êdzɹ¦ÀûÓô˷ì϶±ØÒªÖÎÀíÔ±ÆôÓá°±£ÁôÍ·ÏñΪÎļþ¡±Ñ¡Ïî(¸ÃÑ¡ÏîĬÈϱ»½ûÓÃ)¡£


ͨ¹ýÍøÂç¿Õ¼äËÑË÷ÒýÇæÄܹ»µÃÖª£¬ÔÚÈ«ÇòÁìÓòÄÚ£¬¶Ô»¥ÁªÍøÊ¢¿ªµÄvBulletinÍøÕ¾Óнü3Íò¸ö£¬ÆäÖн϶àÍøÕ¾Îª¹ú¼Ê´óÐÍÆóÒµËùÊØ»¤µÄ¹ú¼ÊÉçÇøÂÛ̳£¬ËùÒԸ÷ì϶ӰÏìÃæ½Ï´ó¡£


·ì϶ÑéÖ¤


CVE-2019-17132

POC£ºhttps://packetstormsecurity.com/files/154759/vBulletin-5.5.4-Remote-Code-Execution.html¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬²¹¶¡»ñÈ¡Á´½Ó£º

https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4423646-vbulletin-5-5-x-5-5-2-5-5-3-and-5-5-4-security-patch-level-2¡£


²Î¿¼Á´½Ó


https://packetstormsecurity.com/files/154758/vBulletin-5.5.4-SQL-Injection.html

https://packetstormsecurity.com/files/154759/vBulletin-5.5.4-Remote-Code-Execution.html