漏洞描述 【漏洞对象】vBulletin 【涉及版本】vBulletin v5.x 【漏洞描述】 vBulletin中存在一个文件包含问题,可使恶意访问者包含来自vBulletin 服务器的文件并且执行任意 PHP 代码。未经验证的恶意访问者可通过向index.php发出包含 routestring=参数的GET请求,从而触发文件包含漏洞,最终导致远程代码执行漏洞
相关漏洞推荐 CVE-2016-6195: vBulletin <= 4.2.3 - SQL Injection POC 2025-08-01 | vBulletin vBulletin versions 3.6.0 through 4.2.3 are vulnerable to an SQL injection vulnerability in the vBull... CVE-2018-6200: vBulletin - Open Redirect POC 2025-08-01 | vBulletin vBulletin 3.x.x and 4.2.x through 4.2.5 contains an open redirect vulnerability via the redirector.p... CVE-2019-16759: vBulletin 5.0.0-5.5.4 - Remote Command Execution POC 2025-08-01 | vBulletin vBulletin 5.0.0 through 5.5.4 is susceptible to a remote command execution vulnerability via the wid... CVE-2017-1000028: GlassFish LFI POC 2025-09-01 | GlassFish GlassFish是一款强健的商业兼容应用服务器,达到产品级质量,可免费用于开发、部署和重新分发。开发者可以免费获得源代码,还可以对代码进行更改。GlassFish漏洞成因:java语义中会把&quo... CVE-2017-1000486: Primetek Primefaces 5.x - Remote Code Execution POC 2025-09-01 | Primetek Primefaces Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution.