2 Security Vulns Issues - Publishing Suite 4.1.7 combined is Unauth SQL Injection

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • mlitchfield
    New Member
    • Nov 2005
    • 3
    • 3.0.8

    [Forum] 2 Security Vulns Issues - Publishing Suite 4.1.7 combined is Unauth SQL Injection

    There exists two seperate security issues within vBulletin Publishing suite. These issues were tested against Version 4.1.7

    The first vuln allows for unauthenticated editing of vBulletin Content

    The second is a SQL Injection attack, that would normally require CMS Admin rights to access. However, because of vulnerability (1) above, we can use both attacks combined to launch an unauthenticated SQL Injection attack against the vBulletin database

    If you are just using the Classic Forum, and NOT the publishing suite. You are not vulnerable to these attacks.

    Can someone point me to the email address for the security team.

    Thanks in advance

    Mark
  • mlitchfield
    New Member
    • Nov 2005
    • 3
    • 3.0.8

    #2
    Example



    Before this was a simple Test page from Home page.

    I will change it back to Test shortly

    Comment

    • Wayne Luke
      vBulletin Technical Support Lead
      • Aug 2000
      • 74161

      #3
      Please post the details here:


      For privacy please choose Private. You'll still be able to see the issue and provide feedback if needed.
      Translations provided by Google.

      Wayne Luke
      The Rabid Badger - a vBulletin Cloud demonstration site.
      vBulletin 5 API

      Comment

      • mlitchfield
        New Member
        • Nov 2005
        • 3
        • 3.0.8

        #4
        Issue now posted as requested

        Comment

        • Wayne Luke
          vBulletin Technical Support Lead
          • Aug 2000
          • 74161

          #5
          Thank you. The issue is being reviewed.
          Translations provided by Google.

          Wayne Luke
          The Rabid Badger - a vBulletin Cloud demonstration site.
          vBulletin 5 API

          Comment

          widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
          Working...