vBulletin 5.x¶à¸ö¸ßΣ·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-10-11·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-17271£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-17132£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
vBulletin°æ±¾5.0.0µ½×îеÄ5.5.4
·ì϶¸ÅÊö
vBulletinÊÇÃÀ¹úInternet BrandsºÍvBulletin Solutions¹«Ë¾¹²Í¬¿ª·¢µÄÒ»¿î¿ªÔ´µÄóÒ×WebÂÛ̳·¨Ê½¡£
½üÈÕ£¬vBulletin ¹Ù·½°ä²¼ÁËÒ»¸öȫа²È«²¹¶¡£¬¸Ã²¹¶¡½¨¸´ÁËCVE±àºÅΪCVE-2019-17271µÄSQL×¢Èë·ì϶£¬ÒÔ¼°CVE±àºÅΪCVE-2019-17132µÄÔ¶³Ì´úÂëÖ´Ðзì϶¡£
CVE-2019-17271 SQL×¢Èë·ì϶
SQL×¢Èë·ì϶ÊÇÁ½¸ö¡°read in-band and time-based¡±µÄSQL×¢ÈëÎÊÌ⣬ËüÃÇ´æÔÚÓÚÁ½¸ö¶ÀÁ¢µÄ¶ËµãÉÏ£¬ÔÊÐíÓµÓÐÊÜÏÞ¶ÈÌØÈ¨µÄÖÎÀíÔ±´ÓÊý¾Ý¿â¶ÁÈ¡Ãô¸ÐÊý¾Ý¡£
£¨1£©Í¨¹ý¡°where¡±²ÎÊýµÄ¼ü´«µÝµ½¡°ajax/api/hook/getHookList¡±¶ËµãµÄÓû§ÊäÈëÊý¾Ý£¬ÔÚºó¶Ü½øÐÐSQL²éÎÊ֮ǰûÓо¹ýÕýÈ·ÑéÖ¤Óë¹ýÂË¡£Ô¶³Ì¹¥»÷ÕßÄܹ»ÀûÓÃÕâÒ»µã£¬Í¨¹ý¡°read in-band¡±SQL×¢Èë¹¥»÷´ÓÊý¾Ý¿âÖжÁÈ¡Ãô¸ÐÊý¾Ý¡£µ«Êdzɹ¦ÀûÓô˷ì϶±ØÒªÓû§¾ßÓÓ×°canadminproducts¡±»ò¡°canadminstyles¡±µÄÖÎÀíԱȨÏÞ£¬ËÁÒâ×¢²áµÄÓû§ÎÞ¸ÃȨÏÞ¡£
£¨2£©Í¨¹ý¡°where¡±²ÎÊýµÄ¼ü´«µÝµ½¡°ajax/api/widget/getWidgetList¡±¶ËµãµÄÓû§ÊäÈëÊý¾Ý£¬ÔÚºó¶Ü½øÐÐSQL²éÎÊ֮ǰûÓо¹ýÕýÈ·ÑéÖ¤Óë¹ýÂË¡£Ô¶³Ì¹¥»÷ÕßÄܹ»ÀûÓÃÕâÒ»µã£¬Í¨¹ý¡°time-based¡±SQL×¢Èë¹¥»÷´ÓÊý¾Ý¿âÖжÁÈ¡Ãô¸ÐÊý¾Ý¡£µ«Êdzɹ¦ÀûÓô˷ì϶±ØÒªÓû§¾ßÓÓ×±canusesitebuilder¡±µÄÖÎÀíԱȨÏÞ£¬ËÁÒâ×¢²áµÄÓû§ÎÞ¸ÃȨÏÞ¡£
CVE-2019-17132 Ô¶³Ì´úÂëÖ´Ðзì϶
vBulletin forum´¦ÖÃÓû§¸üÐÂÍ·Ïñ(Óû§µÄÓ×ÎÒ×ÊÁÏ¡¢Í¼±ê»òͼÐΰµÊ¾)ÒªÇóʱ´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶£¬¸Ã·ì϶²úÉúµÄÔÒòÊÇͨ¹ý¡°data[extension]¡±ºÍ¡°data[filedata]¡±²ÎÊý´«µÝµ½¡±ajax/api/User/updateAvatar¡±¶ËµãµÄÓû§ÊäÈëÊý¾Ý£¬ÔÚÓÃÓÚ¸üÐÂÓû§µÄavatar֮ǰûÓеõ½ÕýÈ·ÑéÖ¤¡£ÕâÄܹ»ÓÃÀ´×¢ÈëºÍÖ´ÐÐËÁÒâµÄPHP´úÂë¡£µ«Êdzɹ¦ÀûÓô˷ì϶±ØÒªÖÎÀíÔ±ÆôÓá°±£ÁôÍ·ÏñΪÎļþ¡±Ñ¡Ïî(¸ÃÑ¡ÏîĬÈϱ»½ûÓÃ)¡£
ͨ¹ýÍøÂç¿Õ¼äËÑË÷ÒýÇæÄܹ»µÃÖª£¬ÔÚÈ«ÇòÁìÓòÄÚ£¬¶Ô»¥ÁªÍøÊ¢¿ªµÄvBulletinÍøÕ¾Óнü3Íò¸ö£¬ÆäÖн϶àÍøÕ¾Îª¹ú¼Ê´óÐÍÆóÒµËùÊØ»¤µÄ¹ú¼ÊÉçÇøÂÛ̳£¬ËùÒԸ÷ì϶ӰÏìÃæ½Ï´ó¡£
·ì϶ÑéÖ¤
CVE-2019-17132
POC£ºhttps://packetstormsecurity.com/files/154759/vBulletin-5.5.4-Remote-Code-Execution.html¡£
½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬²¹¶¡»ñÈ¡Á´½Ó£º
https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4423646-vbulletin-5-5-x-5-5-2-5-5-3-and-5-5-4-security-patch-level-2¡£
²Î¿¼Á´½Ó
https://packetstormsecurity.com/files/154758/vBulletin-5.5.4-SQL-Injection.html
https://packetstormsecurity.com/files/154759/vBulletin-5.5.4-Remote-Code-Execution.html


¾©¹«Íø°²±¸11010802024551ºÅ