vBulletin 5.5.2 PHP Object Injection...

- AV AC AU C I A
发布: 2022-11-28
修订: 2022-12-19

vBulletin versions 5.5.2 and below suffers from an issue where user input passed through the "messageids" request parameter to /ajax/api/vb4_private/movepm is not properly sanitized before being used in a call to the unserialize() PHP function. This can be exploited by malicious users to inject arbitrary PHP objects into the application scope, allowing them to carry out a variety of attacks, such as executing arbitrary PHP code.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息