(CVE-2020-17496) vBulletin 5.x Widget_tabbedcontainer_tab_panel RCE Vuln Test script# vBulletin_5.x-tab_panel-RCE
[CVE-2020-17496] is a vulnerability in vBulletin’s ajax/render/widget_php route by injecting malicious code via the widgetConfig parameter.
Affected System
vBulletin 5.5.4 ~ 5.6.2
vBulletin 5.x Widget_tabbedcontainer_tab_panel RCE Vuln Test script
Usage>
python vBulletin_5.x-tab_panel-RCE.py <dst_ip> <dst_port> (user defined port)
python vBulletin_5.x-tab_panel-RCE.py <dst_ip> (default : 80/tcp)
Script is working on Python3 (2020.11.07 updated)
Just using Vuln Test for your System
[4.0K] /data/pocs/b03627f11317c4e49e6cd8beea00e1c2d560ea5e
├── [ 541] README.md
└── [ 912] vBulletin_5.x-tab_panel-RCE.py
0 directories, 2 files