PT-2007-2956 · Vbulletin Solutions · Vbulletin

Publicado

2007-03-21

·

Atualizado

2018-10-16

·

CVE-2007-1573

CVSS v2.0

6.0

Média

VetorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions vBulletin version 3.6.5
Description The issue allows remote authenticated administrators to execute arbitrary SQL commands. This is achieved via the Attached Before field in the admincp/attachment.php script.
Recommendations For version 3.6.5, consider restricting access to the admincp/attachment.php script until a fix is available, and avoid using the Attached Before field to minimize the risk of exploitation.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-1573

Produtos afetados

Vbulletin