漏洞描述 【漏洞对象】VBulletin 【涉及版本】3.6.x ~ 4.2.1, 4.2.2 ~ 4.2.2 Patch Level 5,4.2.3 ~ 4.2.3Patch Level 1 【漏洞描述】VBulletin核心插件forumrunner存在SQL注入漏洞,该插件默认开启,攻击者在未登录状态即可利用该漏洞进行数据库拖库。
相关漏洞推荐 CVE-2019-16759: vBulletin v5.0.0-v5.5.4 Remote Command Execution POC CVE-2016-6195: vBulletin <= 4.2.3 - SQL Injection POC CVE-2018-6200: vBulletin - Open Redirect POC CVE-2019-16759: vBulletin 5.0.0-5.5.4 - Remote Command Execution POC CVE-2020-12720: vBulletin SQL Injection POC CVE-2020-17496: vBulletin 5.5.4 - 5.6.2- Remote Command Execution POC CVE-2023-25135: vBulletin <= 5.6.9 - Pre-authentication Remote Code Execution POC CVE-2025-48827: vBulletin 5.0.0-6.0.3 - Authentication Bypass POC CVE-2025-48828: vBulletin replaceAdTemplate - Remote Code Execution POC vbulletin-ajaxreg-sqli: vBulletin 3.x / 4.x AjaxReg - SQL Injection POC vbulletin-backdoor: vBulletin Backdoor - Detect POC vbulletin-search-sqli: vBulletin `Search.php` - SQL Injection vBulletin replaceAdTemplate 存在远程代码执行漏洞(CVE-2025-48828)