Exploitation in vBulletin allows remote command execution

Overview :
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig parameter in an ajax/render/widget_php routestring request.
Affected Product(s) :
  • vBulletin 5.x through 5.5.4
Vulnerability Details :
CVE ID : CVE-2019-16759
A specific utility may allow an attacker to gain remote command execution to privileged files.

Solution :

Updates are available by contacting the sales support channel or by contacting the vBulletin support team at support@vBulletin.com

Common Vulnerabilityies and Exposures

Contact us to get started

CVE-2022-2641 : HORNER AUTOMATION RCC 972 15.40 HARD-CODED KEY

CVE-2022-2641 : HORNER AUTOMATION RCC 972 15.40 HARD-CODED KEY

Description Horner Automation’s RCC 972 with firmware version 15.40 has a static encryption key on the device. This could allow

CVE-2022-3270 : FESTO VTEM-S1 INSUFFICIENT TECHNICAL DOCUMENTATION

CVE-2022-3270 : FESTO VTEM-S1 INSUFFICIENT TECHNICAL DOCUMENTATION

Description In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead

CVE-2022-4221 : ASUS NAS-M25 UP TO 1.0.1.7 COOKIE OS COMMAND INJECTION

CVE-2022-4221 : ASUS NAS-M25 UP TO 1.0.1.7 COOKIE OS COMMAND INJECTION

Description Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) vulnerability in Asus NAS-M25 allows an