This site is deprecated. Please
CLICK HERE for latest updates
Short Name |
HTTP:PHP:VBULLETIN-CODE-EXEC
|
Severity |
Minor
|
Recommended |
No
|
Category |
HTTP
|
Keywords |
vBulletin PHP Code Execution
|
Release Date |
2005/03/02
|
Update Number |
1213
|
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+
|
HTTP: vBulletin PHP Code Execution
This signature detect an attack against the vbulletin Web application. Successful exploitation of this vulnerability can lead to an arbitrary code execution within the context of the Web server.
Extended Description
vBulletin is reported prone to an arbitrary PHP script code execution vulnerability. The issue is reported to exist due to a lack of sufficient input sanitization performed on user-supplied data before this data is included in a dynamically generated script.
This vulnerability is reported to affect vBulletin board versions up to and including 3.0.6 that are configured with 'Add Template Name in HTML Comments' functionality enabled.
Affected Products
- Vbulletin vbulletin 1.0.1 lite
- Vbulletin vbulletin 2.0.0 rc 2
- Vbulletin vbulletin 2.0.0 rc 3
- Vbulletin vbulletin 2.0.3
- Vbulletin vbulletin 2.2.0 .0
- Vbulletin vbulletin 2.2.1
- Vbulletin vbulletin 2.2.2
- Vbulletin vbulletin 2.2.3
- Vbulletin vbulletin 2.2.4
- Vbulletin vbulletin 2.2.5
- Vbulletin vbulletin 2.2.6
- Vbulletin vbulletin 2.2.7
- Vbulletin vbulletin 2.2.8
- Vbulletin vbulletin 2.2.9
- Vbulletin vbulletin 2.3.0 .0
- Vbulletin vbulletin 2.3.2
- Vbulletin vbulletin 2.3.3
- Vbulletin vbulletin 2.3.4
- Vbulletin vbulletin 3.0.0
- Vbulletin vbulletin 3.0.0 Beta 2
- Vbulletin vbulletin 3.0.0 Beta 3
- Vbulletin vbulletin 3.0.0 Beta 4
- Vbulletin vbulletin 3.0.0 Beta 5
- Vbulletin vbulletin 3.0.0 Beta 6
- Vbulletin vbulletin 3.0.0 Beta 7
- Vbulletin vbulletin 3.0.0 Gamma
- Vbulletin vbulletin 3.0.1
- Vbulletin vbulletin 3.0.2
- Vbulletin vbulletin 3.0.3
- Vbulletin vbulletin 3.0.4
- Vbulletin vbulletin 3.0.5
- Vbulletin vbulletin 3.0.6
References