Remote PHP Code Execution Vulnerability in vBulletin by vBulletin Solutions
CVE-2017-17671

9.8CRITICAL

Key Information:

Vendor

Vbulletin

Status
Vendor
CVE Published:
14 December 2017

What is CVE-2017-17671?

vBulletin versions up to 5.3.x for Windows are vulnerable to remote PHP code execution due to a flaw in the handling of require_once calls. This vulnerability allows an unauthenticated attacker to exploit directory traversal sequences in crafted requests, effectively bypassing restrictions on standard traversal techniques and enabling access to arbitrary files. By manipulating the HTTP request, an attacker can inject PHP code into log files, potentially leading to compromise of the application and the underlying system.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.