Multiple vBulletin products are prone to an SQL-injection vulnerability because the applications fail to properly sanitize user-supplied input before using it in an SQL query.
Credit:
The original article can be found at: http://www.securityfocus.com/bid/48815
Vulnerable Systems:
* VBulletin vBulletin Publishing Suite 4.1.2 PL1
* VBulletin vBulletin Publishing Suite 4.1.1 PL1
* VBulletin vBulletin Publishing Suite 4.1.0 PL3
* VBulletin vBulletin Publishing Suite 4.0.8 PL3
* VBulletin vBulletin Publishing Suite 4.0.7 PL1
* VBulletin vBulletin Publishing Suite 4.0.6 PL1
* VBulletin vBulletin Publishing Suite 4.0.5 PL1
* VBulletin vBulletin Publishing Suite 4.0.4 PL2
* VBulletin vBulletin Publishing Suite 4.0.3 PL2
* VBulletin vBulletin Publishing Suite 4.0.2 PL5
* VBulletin vBulletin Publishing Suite 4.0.1 PL1
* VBulletin vBulletin Publishing Suite 4.0.0 PL2
* VBulletin VBulletin 4.0.2
* VBulletin VBulletin 4.0.1
* VBulletin VBulletin 4.0 PL 1
* VBulletin VBulletin 4.1.2 PL1
* VBulletin VBulletin 4.1.1 PL1
* VBulletin VBulletin 4.1.0 PL3
* VBulletin VBulletin 4.0.8 PL3
* VBulletin VBulletin 4.0.8
* VBulletin VBulletin 4.0.7 PL1
* VBulletin VBulletin 4.0.6 PL1
* VBulletin VBulletin 4.0.5 PL1
* VBulletin VBulletin 4.0.4 PL2
* VBulletin VBulletin 4.0.3 PL2
* VBulletin VBulletin 4.0.2 PL5
* VBulletin VBulletin 4.0.2 PL 4
* VBulletin VBulletin 4.0.2 PL 3
* VBulletin VBulletin 4.0.2 PL 2
* VBulletin VBulletin 4.0.1 PL1
* VBulletin VBulletin 4.0.0 PL2
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
Vendor Status:
vBulletin as issued an update for this vulnerablity
Patch Availability:
https://www.vbulletin.com/order/index.php
Disclosure Timeline:
Initial Release Jul 20 2011
Please enable JavaScript to view the comments powered by Disqus.
blog comments powered by