PT-2014-4436 · Vbulletin Solutions · Vbulletin

Tintinweb

·

Published

2014-10-15

·

Updated

2015-08-13

·

CVE-2014-2022

CVSS v2.0

7.1

High

VectorAV:N/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions vBulletin versions 4.2.2, 4.2.1, 4.2.0 PL2, and earlier
Description The issue allows remote authenticated users to execute arbitrary SQL commands. This is achieved via the conceptid argument in an xmlrpc API request to the "includes/api/4/breadcrumbs create.php" endpoint.
Recommendations For versions 4.2.2, 4.2.1, and 4.2.0 PL2, and all earlier versions, consider restricting access to the breadcrumbs create.php file until a fix is available. As a temporary workaround, avoid using the conceptid argument in xmlrpc API requests to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-2022

Affected Products

Vbulletin