(CVE-2020-17496) vBulletin 5.x Widget_tabbedcontainer_tab_panel RCE Vuln Test script
# vBulletin_5.x-tab_panel-RCE
[CVE-2020-17496] is a vulnerability in vBulletin’s ajax/render/widget_php route by injecting malicious code via the widgetConfig parameter.
Affected System
vBulletin 5.5.4 ~ 5.6.2
vBulletin 5.x Widget_tabbedcontainer_tab_panel RCE Vuln Test script
Usage>
python vBulletin_5.x-tab_panel-RCE.py <dst_ip> <dst_port> (user defined port)
python vBulletin_5.x-tab_panel-RCE.py <dst_ip> (default : 80/tcp)
Script is working on Python3 (2020.11.07 updated)
Just using Vuln Test for your System
登录后查看神龙缓存的 POC 文件快照
登录查看