Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-48827 PoC — Internet Brands vBulletin 安全漏洞

Source
Associated Vulnerability
Title: Internet Brands vBulletin 安全漏洞 (CVE-2025-48827)
Description:vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP 8.1 or later, as demonstrated by the /api.php?method=protectedMethod pattern, as exploited in the wild in May 2025.
Description
Vbullettin RCE - CVE-2025-48827
Readme
**Description:**

RCE for Vbullettin versions between 5.0.0 - 5.7.5 and 6.0.0 - 6.0.3 with PHP 8.1

**Futures:**

- Multi thread
- Read from multiple target from file
- Detect vbullettin websites
- Checks vulnerabilit, if succes upload a php webshell


**Detail of usage:**

usage: CVE-2025-48827.py [-h] [--url URL] [--list LIST] [--threads THREADS] [--timeout TIMEOUT]

Identify and upload shell on vBulletin targets.

optional arguments:

  -h, --help         show this help message and exit
  
  --url URL          Single target URL
  
  --list LIST        File with list of targets
  
  --threads THREADS  Threads to use (default: 5)
  
  --timeout TIMEOUT  Request timeout in seconds (default: 10)
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →