Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-17496 PoC — vBulletin 注入漏洞

Source
Associated Vulnerability
Title:vBulletin 注入漏洞 (CVE-2020-17496)
Description:vBulletin是美国InternetBrands和vBulletinSolutions公司的一款基于PHP和MySQL的开源Web论坛程序。 vBulletin 5.5.4版本至5.6.2版本中存在安全漏洞。攻击者可借助带有特制subWidgets数据的ajax/render/widget_tabbedcontainer_tab_panel请求利用该漏洞执行命令。
Description
vBulletin versions 5.5.4 through 5.6.2 allow remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759.
File Snapshot

id: CVE-2020-17496 info: name: vBulletin 5.5.4 - 5.6.2- Remote Command Execution author: pussyc ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.