vBulletin 0dayÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-09-25

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


vBulletin°æ±¾5.0.0µ½×îеÄ5.5.4


Îó²î¸ÅÊö


vBulletinÊÇÃÀ¹úInternet BrandsºÍvBulletin Solutions¹«Ë¾ÅäºÏ¿ª·¢µÄÒ»¿î¿ªÔ´µÄÉÌÒµWebÂÛ̳³ÌÐò¡£¡£¡£¡£¡£¡£¡£¡£


һλÄäÃûÇå¾²Ñо¿Ö°Ô±ÔÚÊܽӴýµÄÂÛ̳Èí¼þvBulletinÖз¢Ã÷δÐÞ²¹µÄ0day²¢Åû¶ÁËÏà¹ØPoC¡£¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤¶ÔÒÑÐû²¼´úÂëµÄÆÊÎö£¬£¬£¬£¬£¬£¬£¬£¬¸Ã0dayÔÊÐí¹¥»÷ÕßÔÚÔËÐÐvBulletinʵÀýµÄЧÀÍÆ÷ÉÏÖ´ÐÐShellÏÂÁî¶øÎÞÐè¾ßÓÐÄ¿µÄÂÛ̳µÄÕË»§¡£¡£¡£¡£¡£¡£¡£¡£Ò²¾ÍÊÇ˵ÕâÊÇÒ»¸ö¡°Ô¤Éí·ÝÑéÖ¤µÄÔ¶³Ì´úÂëÖ´ÐС±Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÊÇÄܹ»¶Ô web ƽ̨Ôì³É×îÑÏÖØÓ°ÏìµÄÇ徲ȱÏÝÀàÐÍÖ®Ò»¡£¡£¡£¡£¡£¡£¡£¡£


Ö»¹ÜvBulletin ÊÇÒ»¿îÉÌÓòúÆ·£¬£¬£¬£¬£¬£¬£¬£¬µ«ËüÈÔÈ»ÊÇ×îÈÈÃÅµÄ web ÂÛ̳Èí¼þ°ü£¬£¬£¬£¬£¬£¬£¬£¬ÆäÊг¡·Ý¶îÒª´óÓÚ¶àÖÖ¿ªÔ´µÄ½â¾ö¼Æ»®Èç phpBB¡¢XenForo¡¢Simple Machines Forum¡¢MyBBµÈ¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚvBulletin±»Áè¼Ý10Íò¸öÔÚÏßÍøÕ¾ËùʹÓ㬣¬£¬£¬£¬£¬£¬£¬Òò´Ë¸ÃÎó²îµÄDZÔÚÓ°Ïì¹æÄ£¼«´ó¡£¡£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


POC£ºhttps://seclists.org/fulldisclosure/2019/Sep/31¡£¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


vBulletin¿ª·¢ÍŶÓÉÐδ¶Ô´ËÊÂÎñ¾ÙÐлØÓ¦¡£¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://securityaffairs.co/wordpress/91689/hacking/unpatched-critical-0-day-vbulletin.html