← Voltar para CVEs
CVE-2017-17672
N/ADescricao
In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certain circumstances, code execution, because of unsafe usage of PHP's unserialize() in vB_Library_Template's cacheTemplates() function, which is a publicly exposed API. This is exploited with the templateidlist parameter to ajax/api/template/cacheTemplates.
Detalhes CVE
Pontuacao CVSS v3.1N/A
Publicado12/14/2017
Ultima modificacao4/20/2025
Fontenvd
Avistamentos honeypot0
Produtos afetados
vbulletin:vbulletin
Fraquezas (CWE)
CWE-502
Referencias
https://blogs.securiteam.com/index.php/archives/3573(cve@mitre.org)
https://www.exploit-db.com/exploits/43362/(cve@mitre.org)
https://blogs.securiteam.com/index.php/archives/3573(af854a3a-2127-422b-91ae-364da2661108)
https://www.exploit-db.com/exploits/43362/(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.