vBulletin 0dayÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-09-25

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


vBulletin°æ±¾5.0.0µ½×îеÄ5.5.4


Îó²î¸ÅÊö


vBulletinÊÇÃÀ¹úInternet BrandsºÍvBulletin Solutions¹«Ë¾ÅäºÏ¿ª·¢µÄÒ»¿î¿ªÔ´µÄÉÌÒµWebÂÛ̳³ÌÐò¡£¡£¡£¡£¡£


һλÄäÃûÇå¾²Ñо¿Ö°Ô±ÔÚÊܽӴýµÄÂÛ̳Èí¼þvBulletinÖз¢Ã÷δÐÞ²¹µÄ0day²¢Åû¶ÁËÏà¹ØPoC¡£¡£¡£¡£¡£Æ¾Ö¤¶ÔÒÑÐû²¼´úÂëµÄÆÊÎö£¬£¬£¬¸Ã0dayÔÊÐí¹¥»÷ÕßÔÚÔËÐÐvBulletinʵÀýµÄЧÀÍÆ÷ÉÏÖ´ÐÐShellÏÂÁî¶øÎÞÐè¾ßÓÐÄ¿µÄÂÛ̳µÄÕË»§¡£¡£¡£¡£¡£Ò²¾ÍÊÇ˵ÕâÊÇÒ»¸ö¡°Ô¤Éí·ÝÑéÖ¤µÄÔ¶³Ì´úÂëÖ´ÐС±Îó²î£¬£¬£¬ÊÇÄܹ»¶Ô web ƽ̨Ôì³É×îÑÏÖØÓ°ÏìµÄÇ徲ȱÏÝÀàÐÍÖ®Ò»¡£¡£¡£¡£¡£


Ö»¹ÜvBulletin ÊÇÒ»¿îÉÌÓòúÆ·£¬£¬£¬µ«ËüÈÔÈ»ÊÇ×îÈÈÃÅµÄ web ÂÛ̳Èí¼þ°ü£¬£¬£¬ÆäÊг¡·Ý¶îÒª´óÓÚ¶àÖÖ¿ªÔ´µÄ½â¾ö¼Æ»®Èç phpBB¡¢XenForo¡¢Simple Machines Forum¡¢MyBBµÈ¡£¡£¡£¡£¡£ÓÉÓÚvBulletin±»Áè¼Ý10Íò¸öÔÚÏßÍøÕ¾ËùʹÓ㬣¬£¬Òò´Ë¸ÃÎó²îµÄDZÔÚÓ°Ïì¹æÄ£¼«´ó¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


POC£ºhttps://seclists.org/fulldisclosure/2019/Sep/31¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


vBulletin¿ª·¢ÍŶÓÉÐδ¶Ô´ËÊÂÎñ¾ÙÐлØÓ¦¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://securityaffairs.co/wordpress/91689/hacking/unpatched-critical-0-day-vbulletin.html