vBulletin 0dayÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-09-25

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


vBulletin°æ±¾5.0.0µ½×îеÄ5.5.4


Îó²î¸ÅÊö


vBulletinÊÇÃÀ¹úInternet BrandsºÍvBulletin Solutions¹«Ë¾ÅäºÏ¿ª·¢µÄÒ»¿î¿ªÔ´µÄÉÌÒµWebÂÛ̳³ÌÐò¡£¡£¡£¡£¡£¡£¡£


һλÄäÃûÇå¾²Ñо¿Ö°Ô±ÔÚÊܽӴýµÄÂÛ̳Èí¼þvBulletinÖз¢Ã÷δÐÞ²¹µÄ0day²¢Åû¶ÁËÏà¹ØPoC¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤¶ÔÒÑÐû²¼´úÂëµÄÆÊÎö£¬£¬£¬£¬£¬£¬¸Ã0dayÔÊÐí¹¥»÷ÕßÔÚÔËÐÐvBulletinʵÀýµÄЧÀÍÆ÷ÉÏÖ´ÐÐShellÏÂÁî¶øÎÞÐè¾ßÓÐÄ¿µÄÂÛ̳µÄÕË»§¡£¡£¡£¡£¡£¡£¡£Ò²¾ÍÊÇ˵ÕâÊÇÒ»¸ö¡°Ô¤Éí·ÝÑéÖ¤µÄÔ¶³Ì´úÂëÖ´ÐС±Îó²î£¬£¬£¬£¬£¬£¬ÊÇÄܹ»¶Ô web ƽ̨Ôì³É×îÑÏÖØÓ°ÏìµÄÇ徲ȱÏÝÀàÐÍÖ®Ò»¡£¡£¡£¡£¡£¡£¡£


Ö»¹ÜvBulletin ÊÇÒ»¿îÉÌÓòúÆ·£¬£¬£¬£¬£¬£¬µ«ËüÈÔÈ»ÊÇ×îÈÈÃÅµÄ web ÂÛ̳Èí¼þ°ü£¬£¬£¬£¬£¬£¬ÆäÊг¡·Ý¶îÒª´óÓÚ¶àÖÖ¿ªÔ´µÄ½â¾ö¼Æ»®Èç phpBB¡¢XenForo¡¢Simple Machines Forum¡¢MyBBµÈ¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚvBulletin±»Áè¼Ý10Íò¸öÔÚÏßÍøÕ¾ËùʹÓ㬣¬£¬£¬£¬£¬Òò´Ë¸ÃÎó²îµÄDZÔÚÓ°Ïì¹æÄ£¼«´ó¡£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


POC£ºhttps://seclists.org/fulldisclosure/2019/Sep/31¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


vBulletin¿ª·¢ÍŶÓÉÐδ¶Ô´ËÊÂÎñ¾ÙÐлØÓ¦¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://securityaffairs.co/wordpress/91689/hacking/unpatched-critical-0-day-vbulletin.html