As cited
Copy frozen at (site build).
vulnerabilities
Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
A public exploit was released on July 27 demonstrating how unauthenticated attackers can reach PHP's eval() function in vBulletin and execute arbitrary code on unpatched servers. The vulnerability affects vBulletin 6.2.1 and earlier, as well as 6.1.6 and earlier versions, and requires no authentication or user interaction.
Why it matters: Organizations running vBulletin forums on affected versions face immediate remote code execution risk from unauthenticated attackers now that exploit code is public; patching to current versions should be an urgent priority.
- Source published
- First seen by Cybersecurity Tracker