漏洞描述 vBulletin 是世界上用户非常广泛的PHP论坛,很多大型论坛都选择vBulletin作为自己的社区。其中vBulletin5nodeId未授权sql注入漏洞,攻击者可通过该漏洞获取服务器权限。
相关漏洞推荐 CVE-2016-6195: vBulletin <= 4.2.3 - SQL Injection POC 2025-08-01 | vBulletin vBulletin versions 3.6.0 through 4.2.3 are vulnerable to an SQL injection vulnerability in the vBull... CVE-2018-6200: vBulletin - Open Redirect POC 2025-08-01 | vBulletin vBulletin 3.x.x and 4.2.x through 4.2.5 contains an open redirect vulnerability via the redirector.p... CVE-2019-16759: vBulletin 5.0.0-5.5.4 - Remote Command Execution POC 2025-08-01 | vBulletin vBulletin 5.0.0 through 5.5.4 is susceptible to a remote command execution vulnerability via the wid... CVE-2020-10199: Nexus Repository before 3.21.2 allows JavaEL Injection POC 2025-09-01 | Nexus Repository 漏洞触发需要任意账户权限 body="Nexus Repository Manager" app="Nexus-Repository-Manager" CVE-2020-11455: LimeSurvey 4.1.11 - Path Traversal POC 2025-09-01 | LimeSurvey LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/a...