vBulletin fixes ridiculously easy to exploit zero-day RCE bug

[correlate]

Level 18
Thread author
Top Poster
Well-known
May 4, 2019
801
A simple one-line exploit has been published for a zero-day pre-authentication remote code execution (RCE) vulnerability in the vBulletin forum software.

vBulletin is an immensely popular online forum software utilized by large brands such as Electronic Arts, Zynga, Sony, Pearl Jam, NASA, Steam, and many more.
 

upnorth

Moderator
Verified
Staff Member
Malware Hunter
Well-known
Jul 27, 2015
5,459
This, does not automatic fix and patch the issue. It's the sites administrators that have to do the actual work manually and implement the patch. People that use or is registered on a vBulletin site/forum should reach out and ask the staff, unless it's already locally announced.
 

[correlate]

Level 18
Thread author
Top Poster
Well-known
May 4, 2019
801
This, does not automatic fix and patch the issue. It's the sites administrators that have to do the actual work manually and implement the patch. People that use or is registered on a vBulletin site/forum should reach out and ask the staff, unless it's already locally announced.
you are right .
Site administrators must bear responsibility, especially in maintaining and securing the site.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top