Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
vBulletin through 5.3.x on Windows allows remote PHP code execution because a require_once call is reachable with an unauthenticated request that can include directory traversal sequences to specify an arbitrary pathname, and because ../ traversal is blocked but ..\ traversal is not blocked. For example, an attacker can make an invalid HTTP request containing PHP code, and then make an index.php?routestring= request with enough instances of ".." to reach an Apache HTTP Server log file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
vBulletin for Windows 安全漏洞
Vulnerability Description
vBulletin for Windows是美国Internet Brands和vBulletin Solutions公司共同开发的一款基于Windows平台的开源商业Web论坛程序。 基于Windows平台的vBulletin through 5.3.x及之前的版本中存在安全漏洞。远程攻击者可利用该漏洞执行PHP代码。
CVSS Information
N/A
Vulnerability Type
N/A