CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3270

As cited

Copy frozen at (site build).

vulnerabilities

Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw

A public exploit was released on July 27 demonstrating how unauthenticated attackers can reach PHP's eval() function in vBulletin and execute arbitrary code on unpatched servers. The vulnerability affects vBulletin 6.2.1 and earlier, as well as 6.1.6 and earlier versions, and requires no authentication or user interaction.

Why it matters: Organizations running vBulletin forums on affected versions face immediate remote code execution risk from unauthenticated attackers now that exploit code is public; patching to current versions should be an urgent priority.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary