vBulletin < 4.2.2 rce "0day" (source: fd)
|
18-08-2015, 20:38
|
|||
|
|||
vBulletin < 4.2.2 rce "0day" (source: fd)
Source: http://seclists.org/fulldisclosure/2015/Aug/58
Denne er ikke ny, men jeg kendte personlig ikke til den før jeg læste den på FullDisclosure: Status: Fixed in some versions. Citer:Remote Upload allows to send arbitrary data to loopback-only services, possibly allowing the execution of arbitrary code Exists in vB4. The remote upload as implemented by the vB_Upload_* classes and vB_vURL (at least in vB 4.2.x, most probably earlier releases are also affected, and vB 5 might be affected as well) does not restrict the destination ports and hosts for remote uploads. This allows an attacker to abuse the function to as a proxy commit TCP port scans on other hosts. Much worse, it also allows to connect to local loopback-only services or to services only exposed on an internal network. GENIALT! |
|||
|
Beskeder i denne tråd |
vBulletin < 4.2.2 rce "0day" (source: fd) - af dagGi - 18-08-2015, 20:38
|
User(s) browsing this thread: 1 Gæst(er)