Posts

Showing posts with the label vbulletin

vBulletin 4 2 3 ForumRunner SQL Injection

vBulletin 4 2 3 ForumRunner SQL Injection ################################################################################################## #Exploit Title : vBulletin <= 4.2.3 SQL Injection (CVE-2016-6195) #Author        : Manish Kishan Tanwar AKA error1046 (https://twitter.com/IndiShell1046) #Date          : 25/08/2015 #Love to       : zero cool,Team indishell,Mannu,Viki,Hardeep Singh,Jagriti,Kishan Singh and ritu rathi #Tested At  : Indishell Lab(originally developed by Dantalion) ##################################################################################################     //////////////////////// /// Overview: ////////////////////////     VBulletin version 3.6.0 through 4.2.3 are vulnerable to SQL injection vulnerability in vBulletin core forumrunner addon. Vulnerability was analized and documented by Dantalion (https://enumerated.wordpre...