Security · 2h ago
Public Exploit Released for vBulletin Pre-Auth Code Execution Flaw
A public exploit has been released for a pre-authentication code execution vulnerability in vBulletin, allowing unauthenticated attackers to execute arbitrary code on unpatched servers. The flaw affects vBulletin versions 6.2.1 and earlier, and 6.1.6 and earlier. No user interaction or administrative access is required for exploitation.
Meridian48 take
The release of a working exploit for this vBulletin flaw underscores the urgency for forum administrators to patch immediately, as the attack surface is wide and exploitation trivial.
Read the full reporting
Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw →
The Hacker News
vbulletincode-execution