漏洞描述 vBulletin是一个强大,灵活并可完全根据自己的需要定制的论坛程序套件。</br>一位匿名安全研究人员公开了 vBulletin 中未修补的 0day漏洞并披露了相关 PoC。根据对已发布代码的分析,该 0day 允许攻击者在运行 vBulletin 实例的服务器上执行 Shell命令而无需具有目标论坛的账户。
相关漏洞推荐 CVE-2019-16759: vBulletin v5.0.0-v5.5.4 Remote Command Execution POC CVE-2016-6195: vBulletin <= 4.2.3 - SQL Injection POC CVE-2018-6200: vBulletin - Open Redirect POC CVE-2019-16759: vBulletin 5.0.0-5.5.4 - Remote Command Execution POC CVE-2020-12720: vBulletin SQL Injection POC CVE-2020-17496: vBulletin 5.5.4 - 5.6.2- Remote Command Execution POC CVE-2023-25135: vBulletin <= 5.6.9 - Pre-authentication Remote Code Execution POC CVE-2025-48827: vBulletin 5.0.0-6.0.3 - Authentication Bypass POC CVE-2025-48828: vBulletin replaceAdTemplate - Remote Code Execution POC vbulletin-ajaxreg-sqli: vBulletin 3.x / 4.x AjaxReg - SQL Injection POC vbulletin-backdoor: vBulletin Backdoor - Detect POC vbulletin-search-sqli: vBulletin `Search.php` - SQL Injection vBulletin replaceAdTemplate 存在远程代码执行漏洞(CVE-2025-48828)