Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
9.8
CVSSv3
CVE-2019-17132
Published: 04/10/2019 Updated: 21/07/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
Subscribe to Vbulletin
Vulnerability Summary
vBulletin up to and including 5.5.4 mishandles custom avatars.
Vulnerability Trend
Vulnerable Product
Search on Vulmon
Subscribe to Product
vbulletin vbulletin
Exploits
Exploit DB: vBulletin 5.0 < 5.5.4 - 'updateAvatar' Remote Code Execution
<?php /* --------------------------------------------------------------------- vBulletin <= 554 (updateAvatar) Remote Code Execution Vulnerability --------------------------------------------------------------------- author: Egidio Romano aka EgiX mail: n0b0d13s[at]gmail[dot]com so ...
Exploit DB: vBulletin 5.5.4 Remote Code Execution
vBulletin versions 554 and below suffers from an updateAvatar remote code execution vulnerability ...
References
CWE-94
CWE-20
https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4423646-vbulletin-5-5-x-5-5-2-5-5-3-and-5-5-4-security-patch-level-2
http://seclists.org/fulldisclosure/2019/Oct/9
http://packetstormsecurity.com/files/154759/vBulletin-5.5.4-Remote-Code-Execution.html
https://nvd.nist.gov
https://www.exploit-db.com/exploits/47475
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-21991
CVE-2024-32674
path traversal
CVE-2023-21987
denial of service
dos
CVE-2024-4647
CVE-2024-25519
CVE-2024-33612
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started