7.5

CVE-2015-7808

Exploit
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in the arguments parameter to ajax/api/hook/decodeArguments.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Vbulletin ≫ Vbulletin Version 5.0.0
Vbulletin ≫ Vbulletin Version 5.0.1
Vbulletin ≫ Vbulletin Version 5.0.2
Vbulletin ≫ Vbulletin Version 5.0.3
Vbulletin ≫ Vbulletin Version 5.0.4
Vbulletin ≫ Vbulletin Version 5.0.5
Vbulletin ≫ Vbulletin Version 5.1.0
Vbulletin ≫ Vbulletin Version 5.1.0 Update rc1
Vbulletin ≫ Vbulletin Version 5.1.1
Vbulletin ≫ Vbulletin Version 5.1.2
Vbulletin ≫ Vbulletin Version 5.1.2 Update beta1
Vbulletin ≫ Vbulletin Version 5.1.2 Update rc1
Vbulletin ≫ Vbulletin Version 5.1.2 Update rc2
Vbulletin ≫ Vbulletin Version 5.1.3
Vbulletin ≫ Vbulletin Version 5.1.3 Update alpha5
Vbulletin ≫ Vbulletin Version 5.1.4
Vbulletin ≫ Vbulletin Version 5.1.5
Vbulletin ≫ Vbulletin Version 5.1.6
Vbulletin ≫ Vbulletin Version 5.1.7
Vbulletin ≫ Vbulletin Version 5.1.8
Vbulletin ≫ Vbulletin Version 5.1.9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 80.64% 0.996
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://blog.checkpoint.com/2015/11/05/check-point-discovers-critical-vbulletin-0-day/
Exploit
http://packetstormsecurity.com/files/134331/vBulletin-5.1.2-Unserialize-Code-Execution.html
Exploit
http://pastie.org/pastes/10527766/text?key=wq1hgkcj4afb9ipqzllsq
Exploit
http://www.rapid7.com/db/modules/exploit/multi/http/vbulletin_unserialize
Exploit
https://blog.sucuri.net/2015/11/vbulletin-exploits-in-the-wild.html
Exploit
https://www.exploit-db.com/exploits/38629/
Exploit