7.5
CVE-2015-7808
- EPSS 80.64%
- Veröffentlicht 24.11.2015 20:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in the arguments parameter to ajax/api/hook/decodeArguments.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 80.64% | 0.996 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://blog.checkpoint.com/2015/11/05/check-point-discovers-critical-vbulletin-0-day/
http://packetstormsecurity.com/files/134331/vBulletin-5.1.2-Unserialize-Code-Execution.html
http://pastie.org/pastes/10527766/text?key=wq1hgkcj4afb9ipqzllsq
http://www.rapid7.com/db/modules/exploit/multi/http/vbulletin_unserialize
https://blog.sucuri.net/2015/11/vbulletin-exploits-in-the-wild.html
https://www.exploit-db.com/exploits/38629/