PT-2006-3300 · Vbulletin Solutions · Vbulletin

Publicado

2006-05-12

·

Atualizado

2018-10-18

·

CVE-2006-2335

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions vBulletin versions prior to 3.5.x
Description The issue allows remote authenticated administrators to gain shell access by uploading a CSS file containing PHP code and then selecting the file via the style chooser, causing the PHP code to be executed. This might be due to direct static code injection.
Recommendations For versions prior to 3.5.x, consider restricting access to the style chooser and uploading of CSS files to prevent potential exploitation until a fix is available. As a temporary workaround, consider disabling the ability to upload CSS files or restrict the use of the style chooser to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-2335

Produtos afetados

Vbulletin