PT-2007-4211 · Vbulletin Solutions · Vbulletin

Publicado

2007-05-30

·

Atualizado

2017-07-29

·

CVE-2007-2911

CVSS v2.0

8.5

Alta

VetorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions vBulletin versions prior to 3.6.6
Description The issue allows remote authenticated administrators to execute arbitrary SQL commands. This is achieved via the search field, specifically the datelineafter variable in the GPC array, within the admincp/attachment.php file.
Recommendations For versions prior to 3.6.6, update to version 3.6.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the admincp/attachment.php file to minimize the risk of exploitation. Avoid using the datelineafter variable in the affected API endpoint until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-2911

Produtos afetados

Vbulletin